Find notable cyber news and cases, enriched with sources, timelines, and signals.

Grandoreiro banking trojan DLL sideloading activity in Latin America

Malware Activity
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

The Grandoreiro banking trojan has resurfaced in Latin America, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to run it through legitimate software. The activity raises infection risk by abusing trusted executables to load a malicious library instead of a clearly hostile file. Acronis TRU observed the activity in May 2026, and June telemetry still showed Mexico as the largest detection source. The loader also used anti-analysis checks, encrypted strings, and delayed C2 contact until environmental checks passed.

Related Happenings

Grandoreiro Latin America DLL sideloading campaign

Campaign
H score32 First: 19.08.2026 17:00 Last: 19.08.2026 17:00 Sources 1

How related: Grandoreiro has resurfaced in a campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to execute the banking trojan through legitimate software.

About this happening: A renewed Grandoreiro campaign is targeting Latin American users, with Mexico accounting for 40% of observed detections and increasing banking-trojan risk across t...

LotusLite backdoor delivered via DLL sideloading

Malware Activity
H score22 First: 21.04.2026 15:00 Last: 21.04.2026 15:00 Sources 1

About this happening: The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...

Latest development: 29.06.2026 18:03

Acronis observed Mustang Panda campaigns against Indian government and hydropower targets using SHARDLOADER, MINIRECON, and ZOHOMURK, with Zoho WorkDrive abused as a command-and-control and exfiltration channel. The activity involved spear-phishing ZIP archives, DLL sideloading through signed binaries such as Solid PDF Creator and Citrix Receiver, and active beaconing from June 12 to June 22, 2026; Acronis also found active compromises inside Indian government networks and worked with CERT-In on notification and cleanup.

CRESCENTHARVEST Windows RAT and info-stealer activity

Malware Activity
H score28 First: 19.02.2026 10:13 Last: 19.02.2026 10:13 Sources 1

About this happening: The CRESCENTHARVEST malware activity centers on version.dll, a Windows RAT and information stealer that can execute commands, log keystrokes, and exfiltrate data. It m...

Timeline

  1. 19.08.2026 17:00 2 articles · 2h ago

    Grandoreiro abuses Duplicate Files Finder to load mingwm10.dll

    Initial Disclosure

    Acronis TRU reported a renewed Grandoreiro campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and June telemetry still showing Mexico as the largest source of detected samples. Attackers abused the legitimate Duplicate Files Finder application in a DLL sideloading chain by renaming it and placing a malicious mingwm10.dll beside legitimate dependencies so the trusted executable loaded the malicious library. The loader also performed extensive anti-analysis checks, used encrypted strings, and delayed C2 contact until environmental checks passed; Acronis could not confirm the initial delivery vector but assessed with moderate confidence that spam was involved.

    Show sources