VYPR
researchPublished Aug 19, 2026· Updated Aug 22, 2026· 4 sources

Grandoreiro Banking Trojan Resurfaces in Mexico Using DLL Sideloading

The Grandoreiro banking trojan has re-emerged with a new campaign targeting Mexico, employing DLL sideloading techniques to infect victims and evade detection.

The notorious Grandoreiro banking trojan has resurfaced, launching a new campaign that heavily targets users in Mexico, which now accounts for a significant 40% of global detections. This resurgence marks a notable adaptation by the threat actor group, especially following a major law enforcement operation in January 2024 that aimed to disrupt their operations. Despite these efforts, Grandoreiro continues to evolve its tactics, techniques, and procedures (TTPs) to maintain its malicious activities.

Researchers from Acronis' Threat Research Unit (TRU) first observed this renewed campaign in May 2026. Telemetry data from June 2026 further solidified Mexico's position as the primary target, with the country generating the largest volume of detected malware samples. This focus on Mexico is not entirely new, as previous Grandoreiro campaigns have also targeted the country, alongside earlier expansions into Spain.

The latest campaign leverages a common yet effective technique: DLL sideloading. Attackers have abused the legitimate 'Duplicate Files Finder' application by renaming it and placing a malicious mingwm10.dll file alongside the application's legitimate dependencies. When the trusted executable runs, it inadvertently loads the malicious DLL, allowing the trojan to execute.

Before initiating contact with its command-and-control (C2) infrastructure, the initial loader employs extensive anti-analysis measures. These checks are designed to detect virtualization environments, sandbox artifacts, security and analysis tools, and specific system configurations. Only after successfully bypassing these checks does the malware attempt to establish communication with its C2 servers.

Furthermore, the malware verifies the victim's public IP address and geolocation, blacklisting traffic from several countries to refine its targeting. While the exact initial delivery vector remains unconfirmed, Acronis assesses with moderate confidence that spam campaigns, often disguised with invoice-like ZIP filenames, have been the primary distribution method, aligning with Grandoreiro's historical patterns.

Encrypted strings are used throughout the malware to complicate analysis efforts. The C2 server was offline during the researchers' investigation, but static analysis of the loader suggests it is designed to retrieve a second-stage payload upon successful communication. The observed telemetry indicates that while overall Grandoreiro activity has not reached its previous peak, the continued evolution and adaptation of its campaigns demonstrate that the threat actor remains resilient and active.

This latest report indicates that the Grandoreiro banking Trojan has resurfaced with a new campaign specifically targeting Mexico. The updated malware incorporates enhanced features designed to evade detection and analysis by security researchers, making it a more persistent threat.

The Grandoreiro banking trojan has resurfaced with a new campaign observed in May that abuses legitimate software, specifically the Duplicate Files Finder application, to execute malicious code via DLL side-loading. This campaign employs extensive anti-analysis measures, including checks for virtualization artifacts and security tools, and uses Google's DNS-over-HTTPS service for C2 communication. Telemetry from late June 2026 indicates that activity remains concentrated in Latin America, with Mexico, Spain, Peru, and Argentina as the primary affected countries, showing a steady but less intense presence than its peak.

The new reporting on Grandoreiro indicates that while its primary focus remains on Latin America, particularly Mexico, the banking trojan has also continued to target financial institutions in Europe and North America. Recent samples have been observed abusing the legitimate Duplicate Files Finder application for DLL sideloading, a technique designed to blend malicious activity with normal software operations and evade detection.

Synthesized by Vypr AI