# Grandoreiro Banking Trojan Resurgence (May 2026) — Dual-Vector DLL Side-Loading & VBS Geofenced Campaign with SGC WebSockets/WebRTC C2 Tunneled Through Google Cloud Pub/Sub, Azure MQTT and AWS MQTT Targeting 20+ Portuguese Banks, Spain, Mexico and LATAM

> Two concurrent Grandoreiro banking-trojan campaigns disclosed by WatchGuard in May 2026 target 20+ Portuguese banks (Caixa Geral de Depositos, Millennium, Novobanco, Santander) plus Revolut and Wise, with secondary impact across Spain, Mexico and Latin America. Campaign 1 abuses DLL side-loading against legitimate carriers (FastStone Image Viewer, MinGW, FreeMat, AbiWord) using four Delphi-11 malicious DLLs (libwebp.dll, mingw10.dll, libffi-6.dll, libpng15.dll) that embed SGC WebSockets / WebRTC components and tunnel C2 traffic through Google Cloud Pub/Sub, Microsoft Azure MQTT and Amazon MQTT to masquerade as legitimate video-conferencing. Campaign 2 lures victims to Contabo-hosted geofenced fake pages that pull an obfuscated VBS loader from MediaFire which displays a fake Adobe Reader update decoy while performing WMI AV enumeration, ip-api[.]com geo-verification, browser Kiosk-Mode hijack, credential theft, keylogging, clipboard monitoring and fake banking overlays. Chinese-language strings are embedded in the binaries despite the operators' historical Brazilian/Spanish-speaking origin.

- **Published:** 2026-05-27T00:00:00Z
- **Last reviewed:** 2026-05-27T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0609
- **ID:** TL-2026-0609
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Grandoreiro operators (Brazil)
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

OVERVIEW

Grandoreiro is one of the most prolific and long-running banking trojan families in the world, operating continuously since 2016 and originating from Brazilian-speaking cybercrime ecosystems before expanding to target Spanish- and Portuguese-language financial institutions across Europe and the Americas. Despite multiple INTERPOL-coordinated takedowns in Spain, Brazil and Argentina (2021 and 2024) that resulted in numerous arrests, the remaining operators have continued to evolve the malware. In May 2026 WatchGuard Threat Lab telemetry surfaced two concurrent, freshly-tooled Grandoreiro campaigns targeting 20+ Portuguese banks, with secondary impact across Spain, Mexico and Latin America. Both campaigns introduce significant tradecraft refinements compared with prior Grandoreiro generations, most notably the use of SGC (Secure Group Chat) WebSockets and WebRTC components embedded in Delphi 11 binaries to tunnel command-and-control traffic over Google Cloud Pub/Sub, Microsoft Azure MQTT and Amazon MQTT broker infrastructure so that malicious C2 sessions appear to enterprise monitoring as legitimate video-conferencing traffic.

CAMPAIGN 1 — DLL SIDE-LOADING WITH CLOUD-DISGUISED C2

Campaign 1 is delivered through targeted phishing emails containing links that redirect victims to attacker-controlled URLs which in turn pull a ZIP archive from dropbox.com / dropboxusercontent.com. The ZIP contains a legitimate signed binary (FastStone Image Viewer, MinGW gcc, FreeMat, or AbiWord) paired with a malicious DLL whose filename matches a legitimate import expected by the carrier executable: libwebp.dll (FastStone Image Viewer), mingw10.dll (MinGW), libffi-6.dll (FreeMat), and libpng15.dll (AbiWord). When the user double-clicks the legitimate executable, Windows resolves the malicious DLL from the application directory before the legitimate system copy, satisfying the classic DLL side-loading primitive (MITRE T1574.002). Each malicious DLL is built in Delphi 11 and statically embeds the SGC (Secure Group Chat) WebSockets / WebRTC component suite — a commercial Indy-based VCL library normally used to build legitimate real-time video and chat applications. Once side-loaded, the DLL initialises an SGC WebSocket / WebRTC client and establishes an encrypted persistent session to one of three cloud broker backends: mingw10.dll uses Google Cloud Pub/Sub, libwebp.dll uses Microsoft Azure with the MQTT protocol, and libffi-6.dll uses Amazon Web Services brokers also over MQTT. By tunnelling C2 over WebSocket/WebRTC framing on common HTTPS/TLS ports to high-reputation cloud SaaS endpoints, the operators trivially bypass IP/domain blocklists, defeat SNI-based filters, and produce network telemetry that is statistically indistinguishable from a Teams, Zoom, Webex or Meet conference. The decision to ship three independent cloud transports across the DLL set also provides resilience: if one cloud provider terminates the abused tenant, the other two channels continue to operate.

Each Delphi 11 DLL carries a substantial anti-analysis layer. Before contacting C2 the loader enumerates installed antivirus and EDR products via WMI queries against root\SecurityCenter2 (SELECT * FROM AntiVirusProduct), checks the computer name and current working directory against a denylist of common sandbox and analyst hostnames (e.g. SANDBOX, MALWARE, VMUSER, JOHN-PC), inspects for the presence of debuggers via IsDebuggerPresent and CheckRemoteDebuggerPresent, queries CPUID and registry keys to detect VMware, VirtualBox, QEMU and Hyper-V environments, and tests for hooked APIs and analyst tooling such as Procmon, Wireshark, Fiddler, x64dbg, OllyDbg and IDA. If any heuristic matches, the loader either silently terminates or executes a benign decoy code path so that automated sandboxes record clean behaviour. When checks pass the malware proceeds to credential theft, keylogging, clipboard monitoring, and the deployment of fake-banking HTML overlays specific to each of the 20+ hardcoded Portuguese, Spanish and LATAM bank brand identifiers. A characteristic Grandoreiro feature observed in this campaign is the on-demand abuse of browser Kiosk Mode (e.g. chrome.exe --kiosk --kiosk-printing) to lock the victim's display behind a single fullscreen window during the credential capture phase so the user cannot navigate away or open task manager easily.

CAMPAIGN 2 — GEOFENCED CONTABO LANDING PAGES AND OBFUSCATED VBS LOADER

Campaign 2 begins with phishing or smishing links pointing to uniaodownloadcnk.online (registered February 2026) and to attacker-controlled Contabo VPS subdomains following the pattern vmi<7-digit-number>.contaboserver.net. These landing pages are server-side geofenced via ip-api.com lookups: visitors whose source IP geolocates to Portugal, Spain, Mexico or specific LATAM countries are served a fake corporate download or invoice page that links to a payload hosted on mediafire.com, while connections from non-target geographies, hosting providers, or research ASNs are served a benign decoy or HTTP 404. The MediaFire payload is a heavily obfuscated VBScript loader (typical Grandoreiro generation: string concatenation, character-code arithmetic, dead-code padding, and randomized variable names). When executed via wscript.exe or cscript.exe the VBS first pops a fake 'Adobe Reader update' modal to retain the victim's attention, performs a second-stage WMI AV enumeration (the same SecurityCenter2 query as Campaign 1), validates geolocation again via hxxp://ip-api[.]com/json, then writes the Grandoreiro Delphi PE to disk under %APPDATA% or %PROGRAMDATA% sub-paths and registers persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, scheduled tasks, or LNK shortcuts placed in the user Startup folder. From that point the implant behaves identically to the Campaign 1 payload, including bank-overlay capability and SGC/WebRTC-style cloud C2.

CHINESE-LANGUAGE STRINGS

WatchGuard reverse engineers identified embedded Chinese-language strings in the Delphi binaries — an anomaly relative to Grandoreiro's historically Brazilian Portuguese and Spanish development heritage. The strings are most plausibly attributable to (a) reuse of third-party Chinese-origin Delphi VCL components that ship with localized resource strings, (b) intentional false-flag artifacts seeded to mislead attribution, or (c) collaboration with or hand-off to Chinese-speaking developers. No evidence yet supports nation-state involvement; attribution remains with financially motivated Brazilian/LATAM cybercrime operators.

TARGETING

Hard-coded brand identifiers and overlay templates target 20+ Portuguese banks including Caixa Geral de Depositos, Millennium BCP, Novobanco and Santander Portugal, alongside Revolut and Wise as cross-border digital banks, with additional templates for Spanish (Santander Spain, BBVA, CaixaBank), Mexican (Banamex, BBVA Mexico) and broader LATAM (Banco do Brasil, Itau, Bradesco) institutions. Sectoral impact is concentrated in retail and SME banking customers but extends to corporate finance staff who are increasingly the entry point for higher-value account takeover and wire fraud.

DEFENDER PRIORITIES

Primary detection opportunities: (1) Anomalous WebSocket/WebRTC sessions from non-browser, non-Teams/Zoom/Webex processes to Google Cloud Pub/Sub (pubsub.googleapis.com), Azure IoT/MQTT brokers (*.azure-devices.net) or AWS IoT MQTT brokers (*.iot.*.amazonaws.com); (2) DLL load events where libwebp.dll, mingw10.dll, libffi-6.dll, or libpng15.dll loads from a user-writable path rather than C:\Program Files\<vendor>\; (3) WMI queries to root\SecurityCenter2 from wscript.exe / cscript.exe or from short-lived process trees; (4) wscript/cscript spawning a PE writer to %APPDATA% or %PROGRAMDATA% with persistence registration to the Run key; (5) browser process launches with --kiosk flags initiated by non-user-interactive parents; (6) outbound HTTP GET to ip-api.com/json from non-browser processes. Network teams should also block uniaodownloadcnk.online, vmi*.contaboserver.net wildcard, and 162.33.177.150 at the perimeter; SOCs should hunt historically for the same indicators against the full Grandoreiro IOC corpus.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1608.001 Stage Capabilities: Upload Malware
- T1566.002 Phishing: Spearphishing Link
- T1189 Drive-by Compromise
- T1204.002 User Execution: Malicious File
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1106 Native API
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1547.009 Boot or Logon Autostart Execution: Shortcut Modification
- T1574.001 DLL
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1622 Debugger Evasion
- T1036.005 Match Legitimate Resource Name or Location
- T1218 System Binary Proxy Execution
- T1056.001 Input Capture: Keylogging
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1056.002 Input Capture: GUI Input Capture
- T1518.001 Software Discovery: Security Software Discovery
- T1082 System Information Discovery
- T1614.001 System Location Discovery: System Language Discovery
- T1614 System Location Discovery
- T1115 Clipboard Data
- T1113 Screen Capture
- T1185 Browser Session Hijacking
- T1071.001 Application Layer Protocol: Web Protocols
- T1102.002 Web Service: Bidirectional Communication
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1105 Ingress Tool Transfer
- T1090.004 Domain Fronting
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft

## Sources

- [Hackers Use Grandoreiro Malware to Target Portuguese Banks and Latin American Companies](https://cybersecuritynews.com/hackers-use-grandoreiro-malware-to-target-portuguese-banks/)
- [WatchGuard Threat Lab — Grandoreiro Banking Trojan technical analysis (report referenced by CSN)](https://www.watchguard.com/wgrd-security-hub/threat-lab)
- [MITRE ATT&CK — Grandoreiro Software Profile S0531](https://attack.mitre.org/software/S0531/)
- [MITRE ATT&CK — Hijack Execution Flow: DLL Side-Loading T1574.002](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK — Web Service Bidirectional Communication T1102.002](https://attack.mitre.org/techniques/T1102/002/)
- [MITRE ATT&CK — Application Layer Protocol: Web Protocols T1071.001](https://attack.mitre.org/techniques/T1071/001/)
- [MITRE ATT&CK — Visual Basic T1059.005](https://attack.mitre.org/techniques/T1059/005/)
- [MITRE ATT&CK — Phishing: Spearphishing Link T1566.002](https://attack.mitre.org/techniques/T1566/002/)
- [ESET — Grandoreiro: How the largest banking trojan from Brazil evolved](https://www.welivesecurity.com/2020/04/28/grandoreiro-how-the-largest-banking-trojan-from-brazil-evolved/)
- [Trend Micro — Banking Trojan Targeting Mexico and Brazil's Banks Continues to Evolve](https://www.trendmicro.com/en_us/research/grandoreiro.html)
- [INTERPOL Operation Grandes Origens — Grandoreiro arrests 2024](https://www.interpol.int/News-and-Events/News/2024/Banking-malware-targeting-Spain-dismantled)
- [MITRE ATT&CK — Browser Session Hijacking T1185](https://attack.mitre.org/techniques/T1185/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0609
