Threat reportMalwareTL-2026-2069

Grandoreiro Banking Trojan Multi-Vector Campaign: ClickFix Delivery via canalmodup.com, Dual DLL Sideloading (GoToMeeting/Nero), PIX QR Interception in Brazil, and Parallel WebRTC/STUN Campaign Targeting Iberian Banks

highACTIVE

Grandoreiro Banking Trojan Multi-Vector Campaign (TL-2026-2069), also tracked as Grandoreiro ClickFix Campaign 2026, is a high-severity malware campaign, first published 2026-04-08. It is attributed to Grandoreiro operators (Brazil) with high confidence, affects Microsoft Windows (7/10/11, Server), maps to 20 MITRE ATT&CK techniques (T1027.001, T1036.005, T1056.001), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
1Grandoreiro operators
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-2069

Threat ID
TL-2026-2069
Also known as
Grandoreiro ClickFix Campaign 2026, Grandoreiro WebRTC Campaign 2026
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Grandoreiro operators
Attribution confidence
HIGH
Nation-state nexus
Brazil
Motivation
FINANCIAL
Target sectors
finance, banking, fintech
Target regions
brazil, mexico, portugal, spain, argentina, Latin America, Europe
Detection rules
9
Indicators of compromise
26

Malware and tooling in Grandoreiro Banking Trojan Multi-Vector Campaign

Malware and tooling: ClearFake, Grandoreiro - S0531

How Grandoreiro Banking Trojan Multi-Vector Campaign works

Grandoreiro, a Delphi-based Brazilian banking trojan active since 2016 and operated as a restricted Malware-as-a-Service, is executing a sustained multi-vector campaign in 2026 expanding from Brazil into Mexico, Portugal, and Spain. The first vector uses ClickFix/ClearFake social engineering at canalmodup.com instructing victims to paste clipboard-injected PowerShell into an elevated command prompt, delivering malicious DLLs sideloaded via GoToMeeting g2mstart.exe and Nero WiFi+Transfer Flexpcis.exe signed binaries. At least 8 major Brazilian banks are targeted with branded overlay attacks, credential theft, PIX QR-code interception, screen capture via Magnification API, and Windows Defender exclusion bypass. A parallel WatchGuard-documented campaign against Iberian and Mexican financial institutions (Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, Santander, Revolut, Wise) uses Delphi 11 DLLs (mingwm10.dll, libwebp.dll, libffi-6.dll, libpng15.dll) with sgcWebSockets and STUN/ICE WebRTC protocols for C2 camouflage to evade deep-packet inspection. The C2 infrastructure (177.136.230.88, AS53107 EVEO S.A., Brazil) remained live as of publication. The malware has targeted over 1,700 banks and 276 crypto wallets across 45 countries since 2024, with triple-DGA domain generation and AES-CTS encryption.

Grandoreiro is a sophisticated Delphi-based banking trojan first observed in 2016, part of the 'Tetrade' group of Brazilian banking malware alongside Guildma, Javali, and Melcoz. It operates under a restricted Malware-as-a-Service model where source code access is tightly controlled to trusted partners, with multiple operators using distinct build IDs and C2 servers. Despite law enforcement actions in Brazil (January 2024), Spain, and Argentina that led to operator arrests, Grandoreiro has proven remarkably resilient, splitting its codebase into a new actively maintained lineage targeting 1,700+ financial institutions across 45 countries and a legacy variant targeting approximately 30 Mexican banks.

The 2026 campaign documented by Breakglass Intelligence (April 8, 2026) represents a material escalation in delivery sophistication. The infection chain begins at canalmodup.com with a three-page ClickFix sequence: a fake Google reCAPTCHA silently copies a malicious PowerShell command to the clipboard via navigator.clipboard.writeText(), followed by a 'Confirmação necessária' page instructing the victim to press Win+R, launch cmd.exe as Administrator (Ctrl+Shift+Enter), paste the clipboard (Ctrl+V), and execute. The victim unknowingly bypasses Mark-of-the-Web, execution policy, and UAC in one action. A third page impersonates Caixa Econômica Federal's 'Módulo Warsaw' security module with a fake error message while the trojan is already being installed.

The delivered p.bat dropper (SHA256: 9ffdbc99) performs UAC bypass via getadmin.vbs (Shell.Application.ShellExecute with runas), downloads payloads from http://177.136.230.88/modulo/ using Net.WebClient.DownloadFile into C:\ProgramData\MSDefender\, adds Windows Defender exclusions for the directory and process via Add-MpPreference, establishes registry persistence under HKLM\...\Run\g2mstart, and launches the abused g2mstart.exe signed binary from LogMeIn. The GoToMeeting chain loads a 43.7MB malicious g2m.dll with Magnification API imports for screen capture, libcurl for HTTP C2, and 42.4MB of embedded .rsrc overlay imagery (92.7% of the file). A parallel Nero WiFi+Transfer chain abuses Flexpcis.exe (signed by Nero AG) with Drivespan.dll. Nine related samples share the same C2 across BAT, VBS, MSI, and direct executable delivery mechanisms.

The malware targets eight Brazilian banks with detailed overlay attacks: Banco do Brasil (4 overlays + QR capture, impersonating Topaz OFD), Bradesco (5 overlays + PISCA, impersonating GAS Tecnologia), Caixa Econômica Federal, Itaú Unibanco (4 overlays with 'Guardião 30 Horas' brand), Santander (4 overlays + QR, impersonating Trusteer IBM), Sicoob, Sicredi, and Unicred. All overlays are professionally branded with legitimate Brazilian banking security logos to maximize victim trust. The TClipboard class specifically enables PIX key and QR code interception for real-time payment fraud.

A separate but related campaign documented by WatchGuard's Secplicity team (May 26, 2026) targets Iberian and Mexican financial institutions with a different technical approach. This variant uses Delphi 11-compiled DLLs that sideload via four legitimate signed binaries: mingwm10.dll and libwebp.dll incorporate the sgcWebSockets library with STUN protocol for NAT traversal, while libffi-6.dll and libpng15.dll use the ICE (Interactive Connectivity Establishment) protocol. The C2 traffic is disguised as legitimate WebRTC web-conferencing data, bypassing standard protocol inspection and deep-packet inspection at firewalls. This campaign's targeted institutions span traditional banks (Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, Santander) and digital finance platforms (Revolut, Wise), demonstrating Grandoreiro's evolution beyond traditional banking targets.

Grandoreiro's technical evolution includes triple Domain Generation Algorithms (DGA) for resilient C2 discovery, AES-256 encryption with Ciphertext Stealing (CTS) mode — the first observed use of CTS in malware — multi-layered decryption (XOR, base64, AES), RealThinClient SDK for scalable HTTP/HTTPS C2 handling, cloud VPS gateway architecture to obscure operator IPs, a 150+ tool blacklist for sandbox/analysis evasion, CAPTCHA verification before payload execution, mouse movement pattern capture to evade ML-based behavioral anti-fraud systems, and binary padding via BMP images totaling 300-400MB to evade sandbox time limits and signature-based detection. A parallel Android RAT (BTMOB, evolved from SpySolr/CraxsRAT) operates as malware-as-a-service ($700/month, $1,200 lifetime) targeting Brazilian and Argentine mobile banking users via fake streaming and cryptocurrency sites, with its toolkit leaked in December 2025.

MITRE ATT&CK techniques used in TL-2026-2069

Defense Evasion

T1027.001 Obfuscated Files or Information: Binary Padding; T1036.005 Match Legitimate Resource Name or Location; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1574.001 DLL

Credential Access

T1056.001 Input Capture: Keylogging; T1539 Steal Web Session Cookie

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1572 Protocol Tunneling; T1573 Encrypted Channel

Collection

T1113 Screen Capture

stealth

T1218.007 System Binary Proxy Execution: Msiexec

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Privilege Escalation

T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control

Initial Access

T1566.002 Spearphishing Link

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Grandoreiro Banking Trojan Multi-Vector Campaign

  • Microsoft — Windows (7/10/11, Server)
    Vulnerable versions: All versions
  • LogMeIn — GoToMeeting (g2mstart.exe v10.18.0.19932)
    Vulnerable versions: v10.18.0 Build 19932
  • Nero AG — Nero WiFi+Transfer (Flexpcis.exe v1.0.3.78)
    Vulnerable versions: v1.0.3.78
  • Banco do Brasil — Online Banking Platform
    Vulnerable versions: All versions
  • Bradesco — Online Banking Platform
    Vulnerable versions: All versions
  • Caixa Econômica Federal — Online Banking Platform
    Vulnerable versions: All versions
  • Itaú Unibanco — Online Banking Platform
    Vulnerable versions: All versions
  • Santander Brasil — Online Banking Platform
    Vulnerable versions: All versions
  • Sicoob — Online Banking Platform
    Vulnerable versions: All versions
  • Sicredi — Online Banking Platform
    Vulnerable versions: All versions

Remediation for Grandoreiro Banking Trojan Multi-Vector Campaign

Immediate actions

  • Block C2 IP 177.136.230.88 and AS53107 (EVEO S.A.) at network perimeter
  • Block domain canalmodup.com and all subdomains at DNS/proxy layer
  • Deploy EDR rules detecting g2mstart.exe or Flexpcis.exe loading DLLs from non-standard directories (not LogMeIn or Nero install paths)
  • Monitor and alert on Add-MpPreference -ExclusionPath commands referencing C:\ProgramData\MSDefender\ or similar paths
  • Block clipboard-injected PowerShell execution chain: CLIP+Win+R+Ctrl+V into cmd.exe as administrator
  • Block HTTP GET requests to /modulo/* paths from internal endpoints

Workarounds

  • Restrict non-admin users from modifying Windows Defender exclusions via Group Policy
  • Enable Windows Defender Attack Surface Reduction rules: Block DLL sideloading via PSExec and WMI commands
  • Block Mediafire and anomalous file-sharing platform downloads at network gateway
  • Restrict clipboard access for untrusted websites via browser group policies (Disable or limit navigator.clipboard.writeText)
  • Monitor HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run for unauthorized entries created by non-admin installers

Longer-term hardening

  • Deploy behavioral detection for anomalous STUN/ICE/WebRTC traffic on endpoints without legitimate conferencing software installed
  • Monitor for DLL sideloading events on abused signed binaries: g2mstart.exe, Flexpcis.exe, and their historical aliases (BackItUp.exe, mssedge.exe, Nabisko.exe, RedeWiFi.exe, V2motortubo.exe)
  • Implement application allowlisting — only permit known-good signed binaries from their original install directories
  • Conduct user awareness training on ClickFix/ClearFake social engineering: fake CAPTCHA pages instructing Win+R+Ctrl+V sequences
  • Monitor for MSI installation from HTTP sources or non-standard download directories
  • Deploy network monitoring for DGA-generated domains with high query volumes to newly registered domains

Timeline of Grandoreiro Banking Trojan Multi-Vector Campaign

  • Grandoreiro first observed in the wild targeting Brazilian banks; Delphi-based, with Portuguese-language source code comments
  • ESET publishes detailed analysis showing Grandoreiro expansion from Brazil to Peru, Mexico, and Spain; documents 300MB+ binary padding technique
  • Brazilian federal police arrest Grandoreiro operators; codebase splits into active updated lineage and legacy Mexico-focused variant
  • Kaspersky documents Grandoreiro targeting 1,700+ banks and 276 crypto wallets across 45 countries; first observed use of AES-Ciphertext Stealing (CTS) mode in malware; triple-DGA; mouse-tracking anti-fraud evasion; 150+ tool blacklist; 150,000+ blocked infections
  • canalmodup.com registered via Register SPA (Italy) with registrant in Aboboda, Portugal; nameservers set to Cloudflare
  • Wildcard Let's Encrypt TLS certificate issued for canalmodup.com
  • Production Let's Encrypt R12 TLS certificate issued for canalmodup.com
  • g2m.dll compiled (PE compile timestamp); FlexpcisInstaller.exe first seen on VirusTotal
  • g2mstart.exe and g2m.dll last modified on C2 server 177.136.230.88
  • MSI droppers (screanb.msi, screen rec.msi, Aplication.msi) first observed on VirusTotal sharing same C2
  • Breakglass Intelligence publishes full technical report on ClickFix/delivery campaign; p.bat submitted to MalwareBazaar by johnk3r (9/75 VT detection); C2 remains live
  • WatchGuard Secplicity publishes report on parallel Grandoreiro campaign targeting Portuguese, Spanish, and Mexican banks via Delphi 11 DLLs with sgcWebSockets and STUN/ICE/WebRTC protocol C2 camouflage
  • The Hacker News publishes combined coverage of both Grandoreiro campaigns and BTMOB Android RAT (ESET); multiple security vendors (Rescana, Cybersecurefox) release advisories

Sources cited for Grandoreiro Banking Trojan Multi-Vector Campaign

Detection coverage for TL-2026-2069

As of 2026-04-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2069 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats