Executive Summary
In May 2026, cybersecurity firms WatchGuard and ESET identified two sophisticated banking trojan campaigns targeting Windows and Android users in Latin America and Europe. The Grandoreiro malware, active since 2016, employs DLL side-loading techniques to infiltrate Windows systems, primarily targeting financial institutions in Portugal. Concurrently, the BTMOB remote access trojan (RAT) compromises Android devices, enabling attackers to exfiltrate sensitive data and gain remote control. These campaigns utilize phishing emails and deceptive websites to distribute malicious payloads, posing significant threats to both individual users and organizations.
The persistence and evolution of these malware families underscore the adaptability of financially motivated threat actors. By leveraging legitimate services and employing advanced evasion techniques, such as WebRTC communications and anti-analysis checks, these campaigns highlight the increasing complexity of modern cyber threats and the necessity for robust, multi-layered security defenses.
Why This Matters Now
The resurgence of Grandoreiro and the emergence of BTMOB illustrate a growing trend of sophisticated malware campaigns targeting financial institutions and users across multiple platforms. This highlights the urgent need for enhanced cybersecurity measures, user education on phishing tactics, and vigilant monitoring of network traffic to detect and mitigate such threats effectively.
Attack Path Analysis
The Grandoreiro malware campaign begins with phishing emails targeting users in Spain, Portugal, and Mexico, leading to the download of malicious files. Upon execution, the malware employs DLL side-loading techniques to load trojanized DLLs, establishing persistence and enabling credential theft. The malware utilizes WebRTC and STUN protocols for peer-to-peer communication, facilitating lateral movement and command and control. Sensitive banking information is exfiltrated through encrypted channels, leading to financial fraud and data breaches.
Kill Chain Progression
Initial Compromise
Description
Phishing emails are sent to users, leading them to download and execute malicious files.
MITRE ATT&CK® Techniques
Phishing
User Execution: Malicious File
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Hijack Execution Flow: DLL Search Order Hijacking
Deobfuscate/Decode Files or Information
Application Layer Protocol: Web Protocols
Process Injection: Dynamic-link Library Injection
OS Credential Dumping: LSASS Memory
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target for Grandoreiro banking trojan campaigns across Latin America and Europe, requiring enhanced egress security and encrypted traffic monitoring capabilities.
Financial Services
Critical exposure to banking trojan attacks targeting financial institutions in Spain, Portugal, Mexico with mobile Android infections necessitating zero trust segmentation.
Telecommunications
Infrastructure vulnerable to lateral movement and command-control communications from banking trojans, requiring multicloud visibility and east-west traffic security controls.
Computer Software/Engineering
Development environments at risk from malware targeting Windows systems, needing threat detection capabilities and Kubernetes security for containerized banking applications.
Sources
- Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Usershttps://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.htmlVerified
- Grandoreiro, Software S0531 | MITRE ATT&CK®https://attack.mitre.org/software/S0531/Verified
- ESET Research joins global operation to disrupt the Grandoreiro banking trojan operating in Latin America and Spainhttps://www.eset.com/us/about/newsroom/press-releases/eset-research-joins-global-operation-to-disrupt-the-grandoreiro-banking-trojan/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the malware's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF may limit the malware's ability to communicate with external command and control servers, reducing the risk of successful initial compromise.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation may limit the malware's ability to escalate privileges by restricting access to critical system components.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security may limit the malware's ability to move laterally by restricting unauthorized peer-to-peer communications.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control may limit the malware's ability to maintain command and control by detecting and restricting unauthorized encrypted communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement may limit the malware's ability to exfiltrate data by restricting unauthorized outbound data transfers.
By constraining the malware's ability to exfiltrate data, the potential for financial fraud and data breaches may be significantly reduced.
Impact at a Glance
Affected Business Functions
- Online Banking Services
- Mobile Banking Applications
- Customer Account Management
- Financial Transactions Processing
Estimated downtime: 7 days
Estimated loss: $3,500,000
Banking credentials and personal information of customers in Spain, Portugal, Mexico, and Brazil.
Recommended Actions
Key Takeaways & Next Steps
- • Implement advanced phishing detection mechanisms to prevent initial compromise.
- • Utilize DLL side-loading detection tools to identify and mitigate privilege escalation attempts.
- • Deploy network segmentation and monitoring to detect and prevent lateral movement.
- • Establish robust command and control traffic analysis to identify malicious communications.
- • Enforce strict data exfiltration policies and monitoring to prevent unauthorized data transfers.



