Threat reportMalwareTL-2026-0609

Grandoreiro Banking Trojan Resurgence (May 2026) — Dual-Vector DLL Side-Loading & VBS Geofenced Campaign with SGC WebSockets/WebRTC C2 Tunneled Through Google Cloud Pub/Sub, Azure MQTT and AWS MQTT Targeting 20+ Portuguese Banks, Spain, Mexico and LATAM

highACTIVE

Grandoreiro Banking Trojan Resurgence (May 2026) (TL-2026-0609), also tracked as Grandoreiro May 2026 Resurgence, is a high-severity malware campaign, first published 2026-05-27. It is attributed to Grandoreiro operators (Brazil) with high confidence, affects Caixa Geral de Depositos Online and mobile banking customers, maps to 35 MITRE ATT&CK techniques (T1027, T1036.005, T1041), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
35MITRE ATT&CK
Actors
1Grandoreiro operators
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-0609

Threat ID
TL-2026-0609
Also known as
Grandoreiro May 2026 Resurgence, WatchGuard Grandoreiro Dual Campaign 2026, Portuguese Banking Trojan Campaign 2026
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Grandoreiro operators
Attribution confidence
HIGH
Nation-state nexus
Brazil
Motivation
FINANCIAL
Target sectors
financial-services, banking, fintech, retail-banking-customers, sme-banking
Target regions
Portugal, Spain, Mexico, Latin America, Europe
Detection rules
9
Indicators of compromise
25

Malware and tooling in Grandoreiro Banking Trojan Resurgence (May 2026)

Malware and tooling: Grandoreiro - S0531, SGC (Secure Group Chat) WebSockets / WebRTC VCL components

How Grandoreiro Banking Trojan Resurgence (May 2026) works

Two concurrent Grandoreiro banking-trojan campaigns disclosed by WatchGuard in May 2026 target 20+ Portuguese banks (Caixa Geral de Depositos, Millennium, Novobanco, Santander) plus Revolut and Wise, with secondary impact across Spain, Mexico and Latin America. Campaign 1 abuses DLL side-loading against legitimate carriers (FastStone Image Viewer, MinGW, FreeMat, AbiWord) using four Delphi-11 malicious DLLs (libwebp.dll, mingw10.dll, libffi-6.dll, libpng15.dll) that embed SGC WebSockets / WebRTC components and tunnel C2 traffic through Google Cloud Pub/Sub, Microsoft Azure MQTT and Amazon MQTT to masquerade as legitimate video-conferencing. Campaign 2 lures victims to Contabo-hosted geofenced fake pages that pull an obfuscated VBS loader from MediaFire which displays a fake Adobe Reader update decoy while performing WMI AV enumeration, ip-api[.]com geo-verification, browser Kiosk-Mode hijack, credential theft, keylogging, clipboard monitoring and fake banking overlays. Chinese-language strings are embedded in the binaries despite the operators' historical Brazilian/Spanish-speaking origin.

OVERVIEW

Grandoreiro is one of the most prolific and long-running banking trojan families in the world, operating continuously since 2016 and originating from Brazilian-speaking cybercrime ecosystems before expanding to target Spanish- and Portuguese-language financial institutions across Europe and the Americas. Despite multiple INTERPOL-coordinated takedowns in Spain, Brazil and Argentina (2021 and 2024) that resulted in numerous arrests, the remaining operators have continued to evolve the malware. In May 2026 WatchGuard Threat Lab telemetry surfaced two concurrent, freshly-tooled Grandoreiro campaigns targeting 20+ Portuguese banks, with secondary impact across Spain, Mexico and Latin America. Both campaigns introduce significant tradecraft refinements compared with prior Grandoreiro generations, most notably the use of SGC (Secure Group Chat) WebSockets and WebRTC components embedded in Delphi 11 binaries to tunnel command-and-control traffic over Google Cloud Pub/Sub, Microsoft Azure MQTT and Amazon MQTT broker infrastructure so that malicious C2 sessions appear to enterprise monitoring as legitimate video-conferencing traffic.

CAMPAIGN 1 — DLL SIDE-LOADING WITH CLOUD-DISGUISED C2

Campaign 1 is delivered through targeted phishing emails containing links that redirect victims to attacker-controlled URLs which in turn pull a ZIP archive from dropbox.com / dropboxusercontent.com. The ZIP contains a legitimate signed binary (FastStone Image Viewer, MinGW gcc, FreeMat, or AbiWord) paired with a malicious DLL whose filename matches a legitimate import expected by the carrier executable: libwebp.dll (FastStone Image Viewer), mingw10.dll (MinGW), libffi-6.dll (FreeMat), and libpng15.dll (AbiWord). When the user double-clicks the legitimate executable, Windows resolves the malicious DLL from the application directory before the legitimate system copy, satisfying the classic DLL side-loading primitive (MITRE T1574.002). Each malicious DLL is built in Delphi 11 and statically embeds the SGC (Secure Group Chat) WebSockets / WebRTC component suite — a commercial Indy-based VCL library normally used to build legitimate real-time video and chat applications. Once side-loaded, the DLL initialises an SGC WebSocket / WebRTC client and establishes an encrypted persistent session to one of three cloud broker backends: mingw10.dll uses Google Cloud Pub/Sub, libwebp.dll uses Microsoft Azure with the MQTT protocol, and libffi-6.dll uses Amazon Web Services brokers also over MQTT. By tunnelling C2 over WebSocket/WebRTC framing on common HTTPS/TLS ports to high-reputation cloud SaaS endpoints, the operators trivially bypass IP/domain blocklists, defeat SNI-based filters, and produce network telemetry that is statistically indistinguishable from a Teams, Zoom, Webex or Meet conference. The decision to ship three independent cloud transports across the DLL set also provides resilience: if one cloud provider terminates the abused tenant, the other two channels continue to operate.

Each Delphi 11 DLL carries a substantial anti-analysis layer. Before contacting C2 the loader enumerates installed antivirus and EDR products via WMI queries against root\SecurityCenter2 (SELECT * FROM AntiVirusProduct), checks the computer name and current working directory against a denylist of common sandbox and analyst hostnames (e.g. SANDBOX, MALWARE, VMUSER, JOHN-PC), inspects for the presence of debuggers via IsDebuggerPresent and CheckRemoteDebuggerPresent, queries CPUID and registry keys to detect VMware, VirtualBox, QEMU and Hyper-V environments, and tests for hooked APIs and analyst tooling such as Procmon, Wireshark, Fiddler, x64dbg, OllyDbg and IDA. If any heuristic matches, the loader either silently terminates or executes a benign decoy code path so that automated sandboxes record clean behaviour. When checks pass the malware proceeds to credential theft, keylogging, clipboard monitoring, and the deployment of fake-banking HTML overlays specific to each of the 20+ hardcoded Portuguese, Spanish and LATAM bank brand identifiers. A characteristic Grandoreiro feature observed in this campaign is the on-demand abuse of browser Kiosk Mode (e.g. chrome.exe --kiosk --kiosk-printing) to lock the victim's display behind a single fullscreen window during the credential capture phase so the user cannot navigate away or open task manager easily.

CAMPAIGN 2 — GEOFENCED CONTABO LANDING PAGES AND OBFUSCATED VBS LOADER

Campaign 2 begins with phishing or smishing links pointing to uniaodownloadcnk.online (registered February 2026) and to attacker-controlled Contabo VPS subdomains following the pattern vmi<7-digit-number>.contaboserver.net. These landing pages are server-side geofenced via ip-api.com lookups: visitors whose source IP geolocates to Portugal, Spain, Mexico or specific LATAM countries are served a fake corporate download or invoice page that links to a payload hosted on mediafire.com, while connections from non-target geographies, hosting providers, or research ASNs are served a benign decoy or HTTP 404. The MediaFire payload is a heavily obfuscated VBScript loader (typical Grandoreiro generation: string concatenation, character-code arithmetic, dead-code padding, and randomized variable names). When executed via wscript.exe or cscript.exe the VBS first pops a fake 'Adobe Reader update' modal to retain the victim's attention, performs a second-stage WMI AV enumeration (the same SecurityCenter2 query as Campaign 1), validates geolocation again via hxxp://ip-api[.]com/json, then writes the Grandoreiro Delphi PE to disk under %APPDATA% or %PROGRAMDATA% sub-paths and registers persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, scheduled tasks, or LNK shortcuts placed in the user Startup folder. From that point the implant behaves identically to the Campaign 1 payload, including bank-overlay capability and SGC/WebRTC-style cloud C2.

CHINESE-LANGUAGE STRINGS

WatchGuard reverse engineers identified embedded Chinese-language strings in the Delphi binaries — an anomaly relative to Grandoreiro's historically Brazilian Portuguese and Spanish development heritage. The strings are most plausibly attributable to (a) reuse of third-party Chinese-origin Delphi VCL components that ship with localized resource strings, (b) intentional false-flag artifacts seeded to mislead attribution, or (c) collaboration with or hand-off to Chinese-speaking developers. No evidence yet supports nation-state involvement; attribution remains with financially motivated Brazilian/LATAM cybercrime operators.

TARGETING

Hard-coded brand identifiers and overlay templates target 20+ Portuguese banks including Caixa Geral de Depositos, Millennium BCP, Novobanco and Santander Portugal, alongside Revolut and Wise as cross-border digital banks, with additional templates for Spanish (Santander Spain, BBVA, CaixaBank), Mexican (Banamex, BBVA Mexico) and broader LATAM (Banco do Brasil, Itau, Bradesco) institutions. Sectoral impact is concentrated in retail and SME banking customers but extends to corporate finance staff who are increasingly the entry point for higher-value account takeover and wire fraud.

DEFENDER PRIORITIES

Primary detection opportunities: (1) Anomalous WebSocket/WebRTC sessions from non-browser, non-Teams/Zoom/Webex processes to Google Cloud Pub/Sub (pubsub.googleapis.com), Azure IoT/MQTT brokers (*.azure-devices.net) or AWS IoT MQTT brokers (*.iot.*.amazonaws.com); (2) DLL load events where libwebp.dll, mingw10.dll, libffi-6.dll, or libpng15.dll loads from a user-writable path rather than C:\Program Files\<vendor>\; (3) WMI queries to root\SecurityCenter2 from wscript.exe / cscript.exe or from short-lived process trees; (4) wscript/cscript spawning a PE writer to %APPDATA% or %PROGRAMDATA% with persistence registration to the Run key; (5) browser process launches with --kiosk flags initiated by non-user-interactive parents; (6) outbound HTTP GET to ip-api.com/json from non-browser processes. Network teams should also block uniaodownloadcnk.online, vmi*.contaboserver.net wildcard, and 162.33.177.150 at the perimeter; SOCs should hunt historically for the same indicators against the full Grandoreiro IOC corpus.

MITRE ATT&CK techniques used in TL-2026-0609

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1622 Debugger Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder; T1547.009 Boot or Logon Autostart Execution: Shortcut Modification

Credential Access

T1056.001 Input Capture: Keylogging; T1056.002 Input Capture: GUI Input Capture; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Execution

T1059.005 Command and Scripting Interpreter: Visual Basic; T1106 Native API; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.004 Domain Fronting; T1102.002 Web Service: Bidirectional Communication; T1105 Ingress Tool Transfer; T1573.002 Encrypted Channel: Asymmetric Cryptography

Discovery

T1082 System Information Discovery; T1518.001 Software Discovery: Security Software Discovery; T1614 System Location Discovery; T1614.001 System Location Discovery: System Language Discovery

Collection

T1113 Screen Capture; T1115 Clipboard Data; T1185 Browser Session Hijacking

Initial Access

T1189 Drive-by Compromise; T1566.002 Phishing: Spearphishing Link

stealth

T1574.001 DLL

Resource Development

T1583 Acquire Infrastructure; T1583.003 Acquire Infrastructure: Virtual Private Server; T1608.001 Stage Capabilities: Upload Malware

Impact

T1657 Financial Theft

Affected products and versions in Grandoreiro Banking Trojan Resurgence (May 2026)

  • Caixa Geral de Depositos — Online and mobile banking customers
    Vulnerable versions: all retail and SME customer channels
  • Millennium BCP — Online and mobile banking customers
    Vulnerable versions: all retail and SME customer channels
  • Novobanco — Online and mobile banking customers
    Vulnerable versions: all retail and SME customer channels
  • Santander — Santander Portugal / Santander Spain online banking
    Vulnerable versions: all retail customer channels
  • Revolut — Revolut web and mobile app customers
    Vulnerable versions: all customer channels
  • Wise — Wise web and mobile app customers
    Vulnerable versions: all customer channels
  • Microsoft — Windows endpoints executing FastStone, MinGW, FreeMat or AbiWord with attacker-supplied DLL
    Vulnerable versions: Windows 10; Windows 11
  • FastStone Soft — FastStone Image Viewer (abused as side-loading carrier)
    Vulnerable versions: versions linking libwebp.dll from app directory
  • MinGW project — MinGW gcc distribution (abused as side-loading carrier)
    Vulnerable versions: distributions referencing mingw10.dll
  • FreeMat — FreeMat numeric computing environment (abused as side-loading carrier)
    Vulnerable versions: versions linking libffi-6.dll from app directory

Remediation for Grandoreiro Banking Trojan Resurgence (May 2026)

Immediate actions

  • Block uniaodownloadcnk.online, the vmi*.contaboserver.net wildcard, and IP 162.33.177.150 at the perimeter and DNS layer
  • Block or sinkhole *.byethost*.com wildcard at corporate DNS unless required for business
  • Alert on outbound HTTP requests to ip-api.com/json from any process that is not a browser or known business tool
  • Quarantine and triage any endpoint where libwebp.dll, mingw10.dll, libffi-6.dll, or libpng15.dll loads from a user-writable directory
  • Search mail gateways for messages linking to dropbox.com / dropboxusercontent.com or mediafire.com over the last 90 days and review user click telemetry

Workarounds

  • Disable WebRTC in enterprise-managed browsers where business does not require it
  • Block download of .vbs and .vbe attachments and from web links at the secure web gateway
  • Disable Windows Script Host for non-admin users via HKLM\Software\Microsoft\Windows Script Host\Settings\Enabled = 0

Longer-term hardening

  • Deploy EDR with behavioral detection capable of correlating SGC WebSocket / WebRTC traffic from non-conferencing parent processes
  • Implement application allow-listing (WDAC, AppLocker) to prevent execution of unsigned Delphi PEs from %APPDATA% and %PROGRAMDATA%
  • Restrict wscript.exe and cscript.exe execution to administratively-defined paths via Software Restriction Policies or AppLocker
  • Egress-filter MQTT (TCP/8883, 1883) and unusual WebSocket destinations to enumerated business cloud tenants only
  • Enable WMI activity logging and forward EID 5857-5861 to SIEM for hunting on SELECT * FROM AntiVirusProduct queries
  • Deploy phishing-resistant MFA (FIDO2/WebAuthn) on all consumer and corporate banking portals to defeat overlay-based credential theft

Weaknesses (CWE) in Grandoreiro Banking Trojan Resurgence (May 2026)

CWE-427, CWE-829, CWE-94

Timeline of Grandoreiro Banking Trojan Resurgence (May 2026)

  • Grandoreiro banking trojan first observed targeting Brazilian banks; family attributed to Brazilian-speaking cybercrime ecosystem.
  • ESET publishes 'Grandoreiro: How the largest banking trojan from Brazil evolved', documenting modular Delphi architecture and expansion to Spain and Mexico.
  • INTERPOL-coordinated arrests in Spain dismantle part of the Grandoreiro operator network; core developers remain at large.
  • Operation Grandes Origens — joint Brazilian Federal Police / INTERPOL action arrests additional operators in Brazil and Argentina; malware operations continue.
  • Trend Micro publishes updated technical analysis of Grandoreiro's evolved loaders and continued targeting of Mexico, Spain and LATAM after the 2024 arrests.
  • Phishing delivery domain uniaodownloadcnk.online registered, later used in Campaign 2 geofenced VBS delivery.
  • WatchGuard Threat Lab telemetry observes a sharp rise in DLL side-loading executions of libwebp.dll, mingw10.dll, libffi-6.dll and libpng15.dll across customer endpoints in Portugal and LATAM.
  • Threadlinqs Intelligence publishes TL-2026-0609 with full MITRE mapping, IOCs and detection guidance for SOC and IR teams.
  • WatchGuard report shared with Cyber Security News discloses two concurrent Grandoreiro campaigns: DLL side-loading with SGC WebSockets/WebRTC cloud C2 and geofenced Contabo+MediaFire VBS loader.
  • As of 2026-05-29, this Grandoreiro dual-vector campaign is ACTIVE — disclosed by WatchGuard/ESET on 2026-05-27 (The Hacker News, CyberSecurityNews) as ongoing against 20+ Portuguese/Spanish/LATAM banks. No CVEs; prior INTERPOL takedowns only partly disrupted the gang and the malware persists with novel cloud-broker WebSocket/WebRTC C2.

Sources cited for Grandoreiro Banking Trojan Resurgence (May 2026)

Detection coverage for TL-2026-0609

As of 2026-05-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0609 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats