Grandoreiro Banking Malware Is Back, Targeting Mexican Bank Customers
A banking Trojan first spotted in 2016 is still active, still stealing money, and now using a trusted file-management tool as cover to slip past security software on computers in Mexico.

Key points
- Grandoreiro, a banking Trojan first discovered in 2016, is running a new campaign aimed at bank customers in Mexico as of mid-2025.
- Security firm Acronis found the malware hiding inside a fake invoice email, delivered alongside a legitimate file-management tool called Duplicate Files Finder.
- IBM counted more than 1,500 banks in 60-plus countries targeted by Grandoreiro in 2024; Kaspersky put the figure at 1,700 banks across 45 countries later that year.
- Brazilian and Spanish police, working with Interpol, arrested five administrators in 2024, but the campaign never fully stopped.
- Acronis says this latest version invests heavily in avoiding detection before doing anything visibly harmful.
Grandoreiro, a piece of malicious software designed to steal online banking passwords and drain accounts, has been caught running a fresh campaign in Mexico. Security vendor Acronis published its findings this week, originally reported by Dark Reading. The picture is one of a criminal operation that took a hit from law enforcement and refused to fold. It's a pattern we've been tracking since May, when Grandoreiro was hitting Spain and Brazil simultaneously.
The malware is a banking Trojan: it quietly sits on a victim's computer, watches what they type on banking websites, can take over their screen remotely, and feeds stolen login details back to its operators. Grandoreiro has done this since at least 2016.
How does the attack reach someone's computer?
Victims receive what looks like a routine invoice email. The attached zip file contains what appear to be a normal PDF and an XML document. Both are decoys.
Also inside the zip is Duplicate Files Finder, a real piece of software that helps tidy up hard drives. The attackers modified it. When a victim opens the program, it quietly loads a hidden malicious component alongside itself. This technique is called DLL sideloading: the malware piggybacks on a trusted application so security tools see a normal program running, not a threat.
That hidden component then checks the computer carefully. It looks at screen resolution, available memory, disk space, how long the machine has been switched on, recent user activity, and whether nearly 50 specific security or analysis tools are installed. If everything looks like a real person's everyday machine rather than a researcher's test environment, it connects to the attackers' remote server and pulls down the main payload.
Only then does the actual theft begin.
Why hasn't this been stopped?
Law enforcement came close. In 2024, Brazilian and Spanish police working with Interpol arrested five administrators. Activity dropped noticeably after that.
The problem is the malware had already spread well beyond one tight-knit group. IBM concluded in 2024 it was probably being sold as malware-as-a-service, meaning criminals could rent access to it the way a business rents software. Kaspersky estimated Grandoreiro and its close relatives accounted for roughly 5% of every banking-Trojan attack globally that year. Rental models are hard to shut down because arrests remove operators, not the code itself.
The version Acronis analysed carries extensive anti-forensics features, tools designed to stop researchers from examining how it works. That extra layer suggests whoever is running this campaign invested real effort in staying hidden. Acronis notes the use of a heavily protected loader also points to a deliberate split between gaining initial access and deploying the malware's longer-term capabilities.
| Year | Milestone |
|---|---|
| 2016 | Grandoreiro first detected, focused on Brazil |
| 2024 (early) | IBM tracks it hitting 1,500-plus banks in 60-plus countries |
| 2024 (late) | Kaspersky counts 1,700 targeted banks across 45 countries |
| January 2024 | Interpol-backed arrests of five administrators in Brazil and Spain |
| Mid-2025 | Acronis confirms new Mexico-focused campaign |
No major vendor currently tracks the group behind this variant under a named APT cluster. Attribution indicators, including Delphi as the coding language and Brazilian Portuguese-speaking developers noted in historical research, suggest Brazilian origin at medium confidence. Capability here is clearly sustained. Intent remains financially motivated rather than espionage-driven.
Should you worry if you bank in Mexico?
Anyone in Mexico or Latin America who banks online should treat unexpected email attachments with real suspicion, even ones dressed up as invoices. Opening a zip from an unknown sender is the most common entry point here. Mexican bank customers are already contending with at least one other active fraud campaign this quarter, so the threat environment is crowded right now.
If you use online banking and notice unfamiliar transactions, contact your bank immediately. Fraud lines in targeted regions can freeze accounts fast. Two-step login verification, where the bank sends a code to your phone each time you sign in, makes stolen passwords far less useful to criminals even when they have them.



