216.73.216.6

Grandoreiro Stealer Targeting Spain and Latin America: Malware Analysis and Decryption Insights

· Published 04/04/2025 19:54 · Modified 07/04/2025 08:05

Export JSON

Essential information

Published
04/04/2025 19:54
Modified
07/04/2025 08:05
Tags
2025-04-04 grandoreiro phishing
Related entities
1 intrusion sets (apt), 18 techniques (mitre), 1 malware, 3 others

Description

A new campaign utilizing the Brazilian stealer has been detected targeting Spain and Latin American countries. The malware, active since 2017, aims to steal sensitive information, including banking credentials and personal data. It employs advanced evasion techniques such as string encryption and anti-sandbox measures. The campaign distributes through emails containing VBS files. Once executed, it performs various checks to evade detection and uses legitimate services for geolocation and DNS resolution. The report provides detailed insights into the malware's behavior and explains the string obfuscation and decryption techniques used in this campaign.

External references