The Containment Era is here. →Explore

Executive Summary

In May 2026, cybersecurity firms WatchGuard and ESET identified two sophisticated banking trojan campaigns targeting Windows and Android users in Latin America and Europe. The Grandoreiro malware, active since 2016, employs DLL side-loading techniques to infiltrate Windows systems, primarily targeting financial institutions in Portugal. Concurrently, the BTMOB remote access trojan (RAT) compromises Android devices, enabling attackers to exfiltrate sensitive data and gain remote control. These campaigns utilize phishing emails and deceptive websites to distribute malicious payloads, posing significant threats to both individual users and organizations.

The persistence and evolution of these malware families underscore the adaptability of financially motivated threat actors. By leveraging legitimate services and employing advanced evasion techniques, such as WebRTC communications and anti-analysis checks, these campaigns highlight the increasing complexity of modern cyber threats and the necessity for robust, multi-layered security defenses.

Why This Matters Now

The resurgence of Grandoreiro and the emergence of BTMOB illustrate a growing trend of sophisticated malware campaigns targeting financial institutions and users across multiple platforms. This highlights the urgent need for enhanced cybersecurity measures, user education on phishing tactics, and vigilant monitoring of network traffic to detect and mitigate such threats effectively.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The Grandoreiro malware primarily targets financial institutions in Portugal, while the BTMOB RAT focuses on Android users in Brazil, aiming to steal sensitive data and gain remote control over devices.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the malware's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The CNSF may limit the malware's ability to communicate with external command and control servers, reducing the risk of successful initial compromise.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust Segmentation may limit the malware's ability to escalate privileges by restricting access to critical system components.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-West Traffic Security may limit the malware's ability to move laterally by restricting unauthorized peer-to-peer communications.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud Visibility & Control may limit the malware's ability to maintain command and control by detecting and restricting unauthorized encrypted communications.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress Security & Policy Enforcement may limit the malware's ability to exfiltrate data by restricting unauthorized outbound data transfers.

Impact (Mitigations)

By constraining the malware's ability to exfiltrate data, the potential for financial fraud and data breaches may be significantly reduced.

Impact at a Glance

Affected Business Functions

  • Online Banking Services
  • Mobile Banking Applications
  • Customer Account Management
  • Financial Transactions Processing
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $3,500,000

Data Exposure

Banking credentials and personal information of customers in Spain, Portugal, Mexico, and Brazil.

Recommended Actions

  • Implement advanced phishing detection mechanisms to prevent initial compromise.
  • Utilize DLL side-loading detection tools to identify and mitigate privilege escalation attempts.
  • Deploy network segmentation and monitoring to detect and prevent lateral movement.
  • Establish robust command and control traffic analysis to identify malicious communications.
  • Enforce strict data exfiltration policies and monitoring to prevent unauthorized data transfers.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image