# Grandoreiro Banking Trojan Multi-Vector Campaign: ClickFix Delivery via canalmodup.com, Dual DLL Sideloading (GoToMeeting/Nero), PIX QR Interception in Brazil, and Parallel WebRTC/STUN Campaign Targeting Iberian Banks

> Grandoreiro, a Delphi-based Brazilian banking trojan active since 2016 and operated as a restricted Malware-as-a-Service, is executing a sustained multi-vector campaign in 2026 expanding from Brazil into Mexico, Portugal, and Spain. The first vector uses ClickFix/ClearFake social engineering at canalmodup.com instructing victims to paste clipboard-injected PowerShell into an elevated command prompt, delivering malicious DLLs sideloaded via GoToMeeting g2mstart.exe and Nero WiFi+Transfer Flexpcis.exe signed binaries. At least 8 major Brazilian banks are targeted with branded overlay attacks, credential theft, PIX QR-code interception, screen capture via Magnification API, and Windows Defender exclusion bypass. A parallel WatchGuard-documented campaign against Iberian and Mexican financial institutions (Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, Santander, Revolut, Wise) uses Delphi 11 DLLs (mingwm10.dll, libwebp.dll, libffi-6.dll, libpng15.dll) with sgcWebSockets and STUN/ICE WebRTC protocols for C2 camouflage to evade deep-packet inspection. The C2 infrastructure (177.136.230.88, AS53107 EVEO S.A., Brazil) remained live as of publication. The malware has targeted over 1,700 banks and 276 crypto wallets across 45 countries since 2024, with triple-DGA domain generation and AES-CTS encryption.

- **Published:** 2026-04-08T00:00:00Z
- **Last reviewed:** 2026-04-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2069
- **ID:** TL-2026-2069
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Grandoreiro operators (Brazil)
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Grandoreiro is a sophisticated Delphi-based banking trojan first observed in 2016, part of the 'Tetrade' group of Brazilian banking malware alongside Guildma, Javali, and Melcoz. It operates under a restricted Malware-as-a-Service model where source code access is tightly controlled to trusted partners, with multiple operators using distinct build IDs and C2 servers. Despite law enforcement actions in Brazil (January 2024), Spain, and Argentina that led to operator arrests, Grandoreiro has proven remarkably resilient, splitting its codebase into a new actively maintained lineage targeting 1,700+ financial institutions across 45 countries and a legacy variant targeting approximately 30 Mexican banks.

The 2026 campaign documented by Breakglass Intelligence (April 8, 2026) represents a material escalation in delivery sophistication. The infection chain begins at canalmodup.com with a three-page ClickFix sequence: a fake Google reCAPTCHA silently copies a malicious PowerShell command to the clipboard via navigator.clipboard.writeText(), followed by a 'Confirmação necessária' page instructing the victim to press Win+R, launch cmd.exe as Administrator (Ctrl+Shift+Enter), paste the clipboard (Ctrl+V), and execute. The victim unknowingly bypasses Mark-of-the-Web, execution policy, and UAC in one action. A third page impersonates Caixa Econômica Federal's 'Módulo Warsaw' security module with a fake error message while the trojan is already being installed.

The delivered p.bat dropper (SHA256: 9ffdbc99) performs UAC bypass via getadmin.vbs (Shell.Application.ShellExecute with runas), downloads payloads from http://177.136.230.88/modulo/ using Net.WebClient.DownloadFile into C:\ProgramData\MSDefender\, adds Windows Defender exclusions for the directory and process via Add-MpPreference, establishes registry persistence under HKLM\...\Run\g2mstart, and launches the abused g2mstart.exe signed binary from LogMeIn. The GoToMeeting chain loads a 43.7MB malicious g2m.dll with Magnification API imports for screen capture, libcurl for HTTP C2, and 42.4MB of embedded .rsrc overlay imagery (92.7% of the file). A parallel Nero WiFi+Transfer chain abuses Flexpcis.exe (signed by Nero AG) with Drivespan.dll. Nine related samples share the same C2 across BAT, VBS, MSI, and direct executable delivery mechanisms.

The malware targets eight Brazilian banks with detailed overlay attacks: Banco do Brasil (4 overlays + QR capture, impersonating Topaz OFD), Bradesco (5 overlays + PISCA, impersonating GAS Tecnologia), Caixa Econômica Federal, Itaú Unibanco (4 overlays with 'Guardião 30 Horas' brand), Santander (4 overlays + QR, impersonating Trusteer IBM), Sicoob, Sicredi, and Unicred. All overlays are professionally branded with legitimate Brazilian banking security logos to maximize victim trust. The TClipboard class specifically enables PIX key and QR code interception for real-time payment fraud.

A separate but related campaign documented by WatchGuard's Secplicity team (May 26, 2026) targets Iberian and Mexican financial institutions with a different technical approach. This variant uses Delphi 11-compiled DLLs that sideload via four legitimate signed binaries: mingwm10.dll and libwebp.dll incorporate the sgcWebSockets library with STUN protocol for NAT traversal, while libffi-6.dll and libpng15.dll use the ICE (Interactive Connectivity Establishment) protocol. The C2 traffic is disguised as legitimate WebRTC web-conferencing data, bypassing standard protocol inspection and deep-packet inspection at firewalls. This campaign's targeted institutions span traditional banks (Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, Santander) and digital finance platforms (Revolut, Wise), demonstrating Grandoreiro's evolution beyond traditional banking targets.

Grandoreiro's technical evolution includes triple Domain Generation Algorithms (DGA) for resilient C2 discovery, AES-256 encryption with Ciphertext Stealing (CTS) mode — the first observed use of CTS in malware — multi-layered decryption (XOR, base64, AES), RealThinClient SDK for scalable HTTP/HTTPS C2 handling, cloud VPS gateway architecture to obscure operator IPs, a 150+ tool blacklist for sandbox/analysis evasion, CAPTCHA verification before payload execution, mouse movement pattern capture to evade ML-based behavioral anti-fraud systems, and binary padding via BMP images totaling 300-400MB to evade sandbox time limits and signature-based detection. A parallel Android RAT (BTMOB, evolved from SpySolr/CraxsRAT) operates as malware-as-a-service ($700/month, $1,200 lifetime) targeting Brazilian and Argentine mobile banking users via fake streaming and cryptocurrency sites, with its toolkit leaked in December 2025.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1218.007 System Binary Proxy Execution: Msiexec
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
- T1685 Disable or Modify Tools
- T1574.001 DLL
- T1027.001 Obfuscated Files or Information: Binary Padding
- T1036.005 Match Legitimate Resource Name or Location
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1056.001 Input Capture: Keylogging
- T1539 Steal Web Session Cookie
- T1113 Screen Capture
- T1071.001 Application Layer Protocol: Web Protocols
- T1572 Protocol Tunneling
- T1573 Encrypted Channel
- T1568.002 Dynamic Resolution: Domain Generation Algorithms
- T1657 Financial Theft

## Sources

- [Join the Click: Grandoreiro and the ClickFix Revolution (GoToMeeting DLL Sideload & PIX QR Interception)](https://intel.breakglass.tech/post/grandoreiro-clickfix-canalmodup-pix-gotomeeting-sideload)
- [WatchGuard Secplicity: Grandoreiro Delphi DLL Side-Loading Campaign (Portuguese, Spanish & Mexican Banks)](https://ctipilot.ch/entries/2026-05-29/watchguard-documents-grandoreiro-s-delphi-dll-side-loading-w/)
- [The Hacker News: Grandoreiro Malware and BTMOB RAT Target Banking Customers in Europe and Latin America](https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html)
- [Kaspersky Securelist: Grandoreiro Banking Trojan — Overview of Recent Versions](https://securelist.com/grandoreiro-banking-trojan/114257/)
- [MITRE ATT&CK: Grandoreiro (S0531)](https://attack.mitre.org/software/S0531/)
- [Grandoreiro and BTMOB: New Banking Trojan Campaigns (WatchGuard / ESET Roundup)](https://cybersecurefox.com/en/grandoreiro-btmob-banking-trojans-webrtc-maas/)
- [Active Exploitation Alert: Grandoreiro Banking Trojan and BTMOB RAT](https://www.rescana.com/post/active-exploitation-alert-grandoreiro-banking-trojan-and-btmob-rat-targeting-windows-and-android-users-in-global-financi)
- [ESET WeLiveSecurity: Grandoreiro — How Engorged Can an EXE Get?](https://www.welivesecurity.com/2020/04/28/grandoreiro-how-engorged-can-exe-get/)
- [Kaspersky Securelist: The Tetrade — Brazilian Banking Malware Goes Global](https://securelist.com/the-tetrade-brazilian-banking-malware/97779/)
- [MalwareBazaar: p.bat sample (SHA256: 9ffdbc990c92e9564bbf8dd727c2540f60aa18868c463e81e361069ad5e53938)](https://bazaar.abuse.ch/sample/9ffdbc990c92e9564bbf8dd727c2540f60aa18868c463e81e361069ad5e53938/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2069
