Threat reportMalwareTL-2026-2069
Grandoreiro Banking Trojan Multi-Vector Campaign: ClickFix Delivery via canalmodup.com, Dual DLL Sideloading (GoToMeeting/Nero), PIX QR Interception in Brazil, and Parallel WebRTC/STUN Campaign Targeting Iberian Banks
Grandoreiro Banking Trojan Multi-Vector Campaign (TL-2026-2069), also tracked as Grandoreiro ClickFix Campaign 2026, is a high-severity malware campaign, first published 2026-04-08. It is attributed to Grandoreiro operators (Brazil) with high confidence, affects Microsoft Windows (7/10/11, Server), maps to 20 MITRE ATT&CK techniques (T1027.001, T1036.005, T1056.001), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 1Grandoreiro operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-2069
- Threat ID
- TL-2026-2069
- Also known as
- Grandoreiro ClickFix Campaign 2026, Grandoreiro WebRTC Campaign 2026
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Grandoreiro operators
- Attribution confidence
- HIGH
- Nation-state nexus
- Brazil
- Motivation
- FINANCIAL
- Target sectors
- finance, banking, fintech
- Target regions
- brazil, mexico, portugal, spain, argentina, Latin America, Europe
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in Grandoreiro Banking Trojan Multi-Vector Campaign
Malware and tooling: ClearFake, Grandoreiro - S0531
How Grandoreiro Banking Trojan Multi-Vector Campaign works
Grandoreiro, a Delphi-based Brazilian banking trojan active since 2016 and operated as a restricted Malware-as-a-Service, is executing a sustained multi-vector campaign in 2026 expanding from Brazil into Mexico, Portugal, and Spain. The first vector uses ClickFix/ClearFake social engineering at canalmodup.com instructing victims to paste clipboard-injected PowerShell into an elevated command prompt, delivering malicious DLLs sideloaded via GoToMeeting g2mstart.exe and Nero WiFi+Transfer Flexpcis.exe signed binaries. At least 8 major Brazilian banks are targeted with branded overlay attacks, credential theft, PIX QR-code interception, screen capture via Magnification API, and Windows Defender exclusion bypass. A parallel WatchGuard-documented campaign against Iberian and Mexican financial institutions (Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, Santander, Revolut, Wise) uses Delphi 11 DLLs (mingwm10.dll, libwebp.dll, libffi-6.dll, libpng15.dll) with sgcWebSockets and STUN/ICE WebRTC protocols for C2 camouflage to evade deep-packet inspection. The C2 infrastructure (177.136.230.88, AS53107 EVEO S.A., Brazil) remained live as of publication. The malware has targeted over 1,700 banks and 276 crypto wallets across 45 countries since 2024, with triple-DGA domain generation and AES-CTS encryption.
Grandoreiro is a sophisticated Delphi-based banking trojan first observed in 2016, part of the 'Tetrade' group of Brazilian banking malware alongside Guildma, Javali, and Melcoz. It operates under a restricted Malware-as-a-Service model where source code access is tightly controlled to trusted partners, with multiple operators using distinct build IDs and C2 servers. Despite law enforcement actions in Brazil (January 2024), Spain, and Argentina that led to operator arrests, Grandoreiro has proven remarkably resilient, splitting its codebase into a new actively maintained lineage targeting 1,700+ financial institutions across 45 countries and a legacy variant targeting approximately 30 Mexican banks.
The 2026 campaign documented by Breakglass Intelligence (April 8, 2026) represents a material escalation in delivery sophistication. The infection chain begins at canalmodup.com with a three-page ClickFix sequence: a fake Google reCAPTCHA silently copies a malicious PowerShell command to the clipboard via navigator.clipboard.writeText(), followed by a 'Confirmação necessária' page instructing the victim to press Win+R, launch cmd.exe as Administrator (Ctrl+Shift+Enter), paste the clipboard (Ctrl+V), and execute. The victim unknowingly bypasses Mark-of-the-Web, execution policy, and UAC in one action. A third page impersonates Caixa Econômica Federal's 'Módulo Warsaw' security module with a fake error message while the trojan is already being installed.
The delivered p.bat dropper (SHA256: 9ffdbc99) performs UAC bypass via getadmin.vbs (Shell.Application.ShellExecute with runas), downloads payloads from http://177.136.230.88/modulo/ using Net.WebClient.DownloadFile into C:\ProgramData\MSDefender\, adds Windows Defender exclusions for the directory and process via Add-MpPreference, establishes registry persistence under HKLM\...\Run\g2mstart, and launches the abused g2mstart.exe signed binary from LogMeIn. The GoToMeeting chain loads a 43.7MB malicious g2m.dll with Magnification API imports for screen capture, libcurl for HTTP C2, and 42.4MB of embedded .rsrc overlay imagery (92.7% of the file). A parallel Nero WiFi+Transfer chain abuses Flexpcis.exe (signed by Nero AG) with Drivespan.dll. Nine related samples share the same C2 across BAT, VBS, MSI, and direct executable delivery mechanisms.
The malware targets eight Brazilian banks with detailed overlay attacks: Banco do Brasil (4 overlays + QR capture, impersonating Topaz OFD), Bradesco (5 overlays + PISCA, impersonating GAS Tecnologia), Caixa Econômica Federal, Itaú Unibanco (4 overlays with 'Guardião 30 Horas' brand), Santander (4 overlays + QR, impersonating Trusteer IBM), Sicoob, Sicredi, and Unicred. All overlays are professionally branded with legitimate Brazilian banking security logos to maximize victim trust. The TClipboard class specifically enables PIX key and QR code interception for real-time payment fraud.
A separate but related campaign documented by WatchGuard's Secplicity team (May 26, 2026) targets Iberian and Mexican financial institutions with a different technical approach. This variant uses Delphi 11-compiled DLLs that sideload via four legitimate signed binaries: mingwm10.dll and libwebp.dll incorporate the sgcWebSockets library with STUN protocol for NAT traversal, while libffi-6.dll and libpng15.dll use the ICE (Interactive Connectivity Establishment) protocol. The C2 traffic is disguised as legitimate WebRTC web-conferencing data, bypassing standard protocol inspection and deep-packet inspection at firewalls. This campaign's targeted institutions span traditional banks (Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, Santander) and digital finance platforms (Revolut, Wise), demonstrating Grandoreiro's evolution beyond traditional banking targets.
Grandoreiro's technical evolution includes triple Domain Generation Algorithms (DGA) for resilient C2 discovery, AES-256 encryption with Ciphertext Stealing (CTS) mode — the first observed use of CTS in malware — multi-layered decryption (XOR, base64, AES), RealThinClient SDK for scalable HTTP/HTTPS C2 handling, cloud VPS gateway architecture to obscure operator IPs, a 150+ tool blacklist for sandbox/analysis evasion, CAPTCHA verification before payload execution, mouse movement pattern capture to evade ML-based behavioral anti-fraud systems, and binary padding via BMP images totaling 300-400MB to evade sandbox time limits and signature-based detection. A parallel Android RAT (BTMOB, evolved from SpySolr/CraxsRAT) operates as malware-as-a-service ($700/month, $1,200 lifetime) targeting Brazilian and Argentine mobile banking users via fake streaming and cryptocurrency sites, with its toolkit leaked in December 2025.
MITRE ATT&CK techniques used in TL-2026-2069
Defense Evasion
T1027.001 Obfuscated Files or Information: Binary Padding; T1036.005 Match Legitimate Resource Name or Location; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1574.001 DLL
Credential Access
T1056.001 Input Capture: Keylogging; T1539 Steal Web Session Cookie
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1572 Protocol Tunneling; T1573 Encrypted Channel
Collection
stealth
T1218.007 System Binary Proxy Execution: Msiexec
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
Initial Access
Impact
defense-impairment
Affected products and versions in Grandoreiro Banking Trojan Multi-Vector Campaign
- Microsoft — Windows (7/10/11, Server)
Vulnerable versions: All versions - LogMeIn — GoToMeeting (g2mstart.exe v10.18.0.19932)
Vulnerable versions: v10.18.0 Build 19932 - Nero AG — Nero WiFi+Transfer (Flexpcis.exe v1.0.3.78)
Vulnerable versions: v1.0.3.78 - Banco do Brasil — Online Banking Platform
Vulnerable versions: All versions - Bradesco — Online Banking Platform
Vulnerable versions: All versions - Caixa Econômica Federal — Online Banking Platform
Vulnerable versions: All versions - Itaú Unibanco — Online Banking Platform
Vulnerable versions: All versions - Santander Brasil — Online Banking Platform
Vulnerable versions: All versions - Sicoob — Online Banking Platform
Vulnerable versions: All versions - Sicredi — Online Banking Platform
Vulnerable versions: All versions
Remediation for Grandoreiro Banking Trojan Multi-Vector Campaign
Immediate actions
- Block C2 IP 177.136.230.88 and AS53107 (EVEO S.A.) at network perimeter
- Block domain canalmodup.com and all subdomains at DNS/proxy layer
- Deploy EDR rules detecting g2mstart.exe or Flexpcis.exe loading DLLs from non-standard directories (not LogMeIn or Nero install paths)
- Monitor and alert on Add-MpPreference -ExclusionPath commands referencing C:\ProgramData\MSDefender\ or similar paths
- Block clipboard-injected PowerShell execution chain: CLIP+Win+R+Ctrl+V into cmd.exe as administrator
- Block HTTP GET requests to /modulo/* paths from internal endpoints
Workarounds
- Restrict non-admin users from modifying Windows Defender exclusions via Group Policy
- Enable Windows Defender Attack Surface Reduction rules: Block DLL sideloading via PSExec and WMI commands
- Block Mediafire and anomalous file-sharing platform downloads at network gateway
- Restrict clipboard access for untrusted websites via browser group policies (Disable or limit navigator.clipboard.writeText)
- Monitor HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run for unauthorized entries created by non-admin installers
Longer-term hardening
- Deploy behavioral detection for anomalous STUN/ICE/WebRTC traffic on endpoints without legitimate conferencing software installed
- Monitor for DLL sideloading events on abused signed binaries: g2mstart.exe, Flexpcis.exe, and their historical aliases (BackItUp.exe, mssedge.exe, Nabisko.exe, RedeWiFi.exe, V2motortubo.exe)
- Implement application allowlisting — only permit known-good signed binaries from their original install directories
- Conduct user awareness training on ClickFix/ClearFake social engineering: fake CAPTCHA pages instructing Win+R+Ctrl+V sequences
- Monitor for MSI installation from HTTP sources or non-standard download directories
- Deploy network monitoring for DGA-generated domains with high query volumes to newly registered domains
Timeline of Grandoreiro Banking Trojan Multi-Vector Campaign
- Grandoreiro first observed in the wild targeting Brazilian banks; Delphi-based, with Portuguese-language source code comments
- ESET publishes detailed analysis showing Grandoreiro expansion from Brazil to Peru, Mexico, and Spain; documents 300MB+ binary padding technique
- Brazilian federal police arrest Grandoreiro operators; codebase splits into active updated lineage and legacy Mexico-focused variant
- Kaspersky documents Grandoreiro targeting 1,700+ banks and 276 crypto wallets across 45 countries; first observed use of AES-Ciphertext Stealing (CTS) mode in malware; triple-DGA; mouse-tracking anti-fraud evasion; 150+ tool blacklist; 150,000+ blocked infections
- canalmodup.com registered via Register SPA (Italy) with registrant in Aboboda, Portugal; nameservers set to Cloudflare
- Wildcard Let's Encrypt TLS certificate issued for canalmodup.com
- Production Let's Encrypt R12 TLS certificate issued for canalmodup.com
- g2m.dll compiled (PE compile timestamp); FlexpcisInstaller.exe first seen on VirusTotal
- g2mstart.exe and g2m.dll last modified on C2 server 177.136.230.88
- MSI droppers (screanb.msi, screen rec.msi, Aplication.msi) first observed on VirusTotal sharing same C2
- Breakglass Intelligence publishes full technical report on ClickFix/delivery campaign; p.bat submitted to MalwareBazaar by johnk3r (9/75 VT detection); C2 remains live
- WatchGuard Secplicity publishes report on parallel Grandoreiro campaign targeting Portuguese, Spanish, and Mexican banks via Delphi 11 DLLs with sgcWebSockets and STUN/ICE/WebRTC protocol C2 camouflage
- The Hacker News publishes combined coverage of both Grandoreiro campaigns and BTMOB Android RAT (ESET); multiple security vendors (Rescana, Cybersecurefox) release advisories
Sources cited for Grandoreiro Banking Trojan Multi-Vector Campaign
- Join the Click: Grandoreiro and the ClickFix Revolution (GoToMeeting DLL Sideload & PIX QR Interception)
- WatchGuard Secplicity: Grandoreiro Delphi DLL Side-Loading Campaign (Portuguese, Spanish & Mexican Banks)
- The Hacker News: Grandoreiro Malware and BTMOB RAT Target Banking Customers in Europe and Latin America
- Kaspersky Securelist: Grandoreiro Banking Trojan — Overview of Recent Versions
- MITRE ATT&CK: Grandoreiro (S0531)
- Grandoreiro and BTMOB: New Banking Trojan Campaigns (WatchGuard / ESET Roundup)
- Active Exploitation Alert: Grandoreiro Banking Trojan and BTMOB RAT
- ESET WeLiveSecurity: Grandoreiro — How Engorged Can an EXE Get?
- Kaspersky Securelist: The Tetrade — Brazilian Banking Malware Goes Global
- MalwareBazaar: p.bat sample (SHA256: 9ffdbc990c92e9564bbf8dd727c2540f60aa18868c463e81e361069ad5e53938)
Detection coverage for TL-2026-2069
As of 2026-04-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2069 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.