Grandoreiro Latin America DLL sideloading campaign
Campaign
Summary
Hide ▲
Show ▼
A renewed Grandoreiro campaign is targeting Latin American users, with Mexico accounting for 40% of observed detections and increasing banking-trojan risk across the region. Attackers used DLL sideloading through the legitimate Duplicate Files Finder application to load a malicious mingwm10.dll. Telemetry from May 2026 and the last 30 days of June showed the activity remained concentrated in Latin America, with smaller clusters in Europe and North America.
Related Happenings
Grandoreiro banking trojan DLL sideloading activity in Latin America
Malware Activity
H score20
First: 19.08.2026 17:00
Last: 19.08.2026 17:00
Sources 1
How related:
Grandoreiro has resurfaced in a campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to execute the banking trojan through legitimate software.
About this happening:
The Grandoreiro banking trojan has resurfaced in Latin America, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to ru...
Grandoreiro banking trojan DLL sideloading activity in Latin America
Malware ActivityHow related: Grandoreiro has resurfaced in a campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to execute the banking trojan through legitimate software.
About this happening: The Grandoreiro banking trojan has resurfaced in Latin America, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to ru...
LotusLite backdoor delivered via DLL sideloading
Malware Activity
H score22
First: 21.04.2026 15:00
Last: 21.04.2026 15:00
Sources 1
About this happening:
The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...
LotusLite backdoor delivered via DLL sideloading
Malware ActivityAbout this happening: The Mustang Panda campaign spans an April 2026 wave against India's banking sector and US-Korea policy circles and a later June 12–22, 2026 wave against Indi...
Latest development: 29.06.2026 18:03
Acronis observed Mustang Panda campaigns against Indian government and hydropower targets using SHARDLOADER, MINIRECON, and ZOHOMURK, with Zoho WorkDrive abused as a command-and-control and exfiltration channel. The activity involved spear-phishing ZIP archives, DLL sideloading through signed binaries such as Solid PDF Creator and Citrix Receiver, and active beaconing from June 12 to June 22, 2026; Acronis also found active compromises inside Indian government networks and worked with CERT-In on notification and cleanup.
Timeline
-
19.08.2026 17:00 2 articles · 2h ago
Grandoreiro resurfaces in Latin America with DLL sideloading
Initial DisclosureAcronis TRU observed a renewed Grandoreiro campaign in May 2026 targeting Latin American users, with Mexico accounting for 40% of observed detections and smaller clusters appearing in Spain, Peru, and Argentina. Attackers abused the legitimate Duplicate Files Finder application in a DLL sideloading chain, renamed the application, and placed a malicious mingwm10.dll beside legitimate dependencies so the trusted executable would load the malicious library. The loader performed extensive anti-analysis checks, used encrypted strings, and contacted C2 only after environmental checks, while the initial delivery vector remained unconfirmed and Acronis assessed with moderate confidence that spam was involved.
Show sources
- Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign — www.infosecurity-magazine.com — 19.08.2026 17:00
- Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign — www.infosecurity-magazine.com — 19.08.2026 17:00