Grandoreiro Banking Malware Is Back, Targeting Mexican Bank Customers

A banking virus first spotted in 2016 is still active, still stealing money, and now using a clever disguise to slip past security software on computers in Mexico.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial overhead shot of a darkened open-plan European office at night, glowing monitors showing abstract email interfaces and red alert indica
Share

Key points

  • Grandoreiro, a banking virus first discovered in 2016, is running a new campaign aimed at bank customers in Mexico as of mid-2025.
  • Security firm Acronis found the malware hiding inside a fake invoice email, delivered alongside a legitimate file-management tool called Duplicate Files Finder.
  • IBM researchers counted more than 1,500 banks in 60-plus countries targeted by Grandoreiro variants in 2024; Kaspersky put the figure at 1,700 banks across 45 countries.
  • Brazilian and Spanish police, working with Interpol, arrested five people running the operation in 2024, but the campaign never fully stopped.
  • Acronis says this latest version is more deliberately stealthy than earlier variants, spending significant effort avoiding detection before it does anything visibly harmful.

Grandoreiro, a piece of malicious software designed to steal online banking passwords and drain accounts, has been caught running a fresh campaign in Mexico. Security vendor Acronis published its findings this week, originally reported by Dark Reading, and the picture is one of a criminal operation that took a hit from law enforcement but refused to fold.

The malware is a banking Trojan, which means it quietly sits on a victim's computer, watches what they type on banking websites, sometimes takes over their screen remotely, and feeds stolen login details back to whoever is running it. Grandoreiro has done this since at least 2016.

How does the attack reach someone's computer?

Victims receive what looks like a routine invoice email. The attached zip file, a compressed folder of files, appears to contain a normal PDF and an XML document. Both are decoys.

Also inside the zip is a copy of Duplicate Files Finder, a real, legitimate piece of software that helps tidy up hard drives. The attackers modified it. When a victim opens the program, it quietly loads a hidden malicious component alongside itself. This technique is called DLL sideloading: the malware piggybacks on a trusted application so security tools see a normal program running, not an obvious threat.

That hidden component then checks the computer carefully. It looks at screen resolution, available memory, how long the machine has been switched on, and whether roughly 50 specific security or analysis tools are installed. If everything looks like a real person's everyday computer rather than a security researcher's testing environment, it connects to the attackers' remote server and pulls down the main Grandoreiro payload.

Only then does the actual theft begin.

Why hasn't this been stopped?

Law enforcement came close. In 2024, Brazilian and Spanish police working with Interpol arrested five administrators running Grandoreiro. Activity dropped noticeably after that.

The problem is the malware had already spread well beyond a single tight-knit group. IBM assessed in 2024 that it was probably being sold as malware-as-a-service, meaning criminals could rent access to it the same way a business rents software. Kaspersky estimated Grandoreiro and its close relatives accounted for roughly 5% of every banking-Trojan attack globally in 2024. Renting models like that are hard to shut down completely because arrests remove operators, not the code itself.

The version Acronis analysed carries significant anti-forensics features, tools designed to stop security researchers from examining how the malware works. That extra layer of protection suggests whoever is running this latest campaign invested real effort in staying hidden.

Year Milestone
2016 Grandoreiro first detected, focused on Brazil
2024 (early) IBM tracks it hitting 1,500-plus banks in 60-plus countries
2024 (late) Kaspersky counts 1,700 targeted banks across 45 countries
January 2024 Interpol-backed arrests of five administrators in Brazil and Spain
Mid-2025 Acronis confirms new Mexico-focused campaign

The group behind this variant is not tracked under a named APT cluster by any major vendor at this time. Attribution indicators, including the use of Delphi as the coding language and Brazilian Portuguese-speaking developers noted in historical research, suggest Brazilian origin at medium confidence. Capability here is clearly sustained. Intent remains financially motivated rather than espionage-driven.

What should ordinary bank customers do?

Anyone in Mexico or Latin America who banks online should be careful about unexpected email attachments, even ones that look like invoices or routine documents. Opening a zip file from an unknown sender is the most common entry point here.

If you use online banking and notice unfamiliar transactions, contact your bank immediately. Banks in targeted regions often have fraud lines that can freeze accounts fast. Turning on two-step login verification, where the bank sends a code to your phone each time you log in, makes stolen passwords far less useful to criminals even if they have them.

© 2026 Threat Vectr