Grandoreiro banking trojan DLL sideloading activity in Latin America
Malware Activity
Summary
Hide ▲
Show ▼
The Grandoreiro banking trojan has resurfaced in Latin America, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to run it through legitimate software. The activity raises infection risk by abusing trusted executables to load a malicious library instead of a clearly hostile file. Acronis TRU observed the activity in May 2026, and June telemetry still showed Mexico as the largest detection source. The loader also used anti-analysis checks, encrypted strings, and delayed C2 contact until environmental checks passed.
Related Happenings
Grandoreiro Latin America DLL sideloading campaign
Campaign
H score32
First: 19.08.2026 17:00
Last: 19.08.2026 17:00
Sources 1
How related:
Grandoreiro has resurfaced in a campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to execute the banking trojan through legitimate software.
About this happening:
A renewed Grandoreiro campaign is targeting Latin American users, with Mexico accounting for 40% of observed detections and increasing banking-trojan risk across t...
Grandoreiro Latin America DLL sideloading campaign
CampaignHow related: Grandoreiro has resurfaced in a campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to execute the banking trojan through legitimate software.
About this happening: A renewed Grandoreiro campaign is targeting Latin American users, with Mexico accounting for 40% of observed detections and increasing banking-trojan risk across t...
LotusLite backdoor delivered via DLL sideloading
Malware Activity
H score22
First: 21.04.2026 15:00
Last: 21.04.2026 15:00
Sources 1
About this happening:
The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...
LotusLite backdoor delivered via DLL sideloading
Malware ActivityAbout this happening: The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...
Latest development: 29.06.2026 18:03
Acronis observed Mustang Panda campaigns against Indian government and hydropower targets using SHARDLOADER, MINIRECON, and ZOHOMURK, with Zoho WorkDrive abused as a command-and-control and exfiltration channel. The activity involved spear-phishing ZIP archives, DLL sideloading through signed binaries such as Solid PDF Creator and Citrix Receiver, and active beaconing from June 12 to June 22, 2026; Acronis also found active compromises inside Indian government networks and worked with CERT-In on notification and cleanup.
CRESCENTHARVEST Windows RAT and info-stealer activity
Malware Activity
H score28
First: 19.02.2026 10:13
Last: 19.02.2026 10:13
Sources 1
About this happening:
The CRESCENTHARVEST malware activity centers on version.dll, a Windows RAT and information stealer that can execute commands, log keystrokes, and exfiltrate data. It m...
CRESCENTHARVEST Windows RAT and info-stealer activity
Malware ActivityAbout this happening: The CRESCENTHARVEST malware activity centers on version.dll, a Windows RAT and information stealer that can execute commands, log keystrokes, and exfiltrate data. It m...
Timeline
-
19.08.2026 17:00 2 articles · 2h ago
Grandoreiro abuses Duplicate Files Finder to load mingwm10.dll
Initial DisclosureAcronis TRU reported a renewed Grandoreiro campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and June telemetry still showing Mexico as the largest source of detected samples. Attackers abused the legitimate Duplicate Files Finder application in a DLL sideloading chain by renaming it and placing a malicious mingwm10.dll beside legitimate dependencies so the trusted executable loaded the malicious library. The loader also performed extensive anti-analysis checks, used encrypted strings, and delayed C2 contact until environmental checks passed; Acronis could not confirm the initial delivery vector but assessed with moderate confidence that spam was involved.
Show sources
- Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign — www.infosecurity-magazine.com — 19.08.2026 17:00
- Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign — www.infosecurity-magazine.com — 19.08.2026 17:00