Grandoreiro Banking Trojan Resurfaces in Mexico Using DLL Sideloading
The Grandoreiro banking trojan has re-emerged with a new campaign targeting Mexico, employing DLL sideloading techniques to infect victims and evade detection.

The notorious Grandoreiro banking trojan has resurfaced, launching a new campaign that heavily targets users in Mexico, which now accounts for a significant 40% of global detections. This resurgence marks a notable adaptation by the threat actor group, especially following a major law enforcement operation in January 2024 that aimed to disrupt their operations. Despite these efforts, Grandoreiro continues to evolve its tactics, techniques, and procedures (TTPs) to maintain its malicious activities.
Researchers from Acronis' Threat Research Unit (TRU) first observed this renewed campaign in May 2026. Telemetry data from June 2026 further solidified Mexico's position as the primary target, with the country generating the largest volume of detected malware samples. This focus on Mexico is not entirely new, as previous Grandoreiro campaigns have also targeted the country, alongside earlier expansions into Spain.
The latest campaign leverages a common yet effective technique: DLL sideloading. Attackers have abused the legitimate 'Duplicate Files Finder' application by renaming it and placing a malicious mingwm10.dll file alongside the application's legitimate dependencies. When the trusted executable runs, it inadvertently loads the malicious DLL, allowing the trojan to execute.
Before initiating contact with its command-and-control (C2) infrastructure, the initial loader employs extensive anti-analysis measures. These checks are designed to detect virtualization environments, sandbox artifacts, security and analysis tools, and specific system configurations. Only after successfully bypassing these checks does the malware attempt to establish communication with its C2 servers.
Furthermore, the malware verifies the victim's public IP address and geolocation, blacklisting traffic from several countries to refine its targeting. While the exact initial delivery vector remains unconfirmed, Acronis assesses with moderate confidence that spam campaigns, often disguised with invoice-like ZIP filenames, have been the primary distribution method, aligning with Grandoreiro's historical patterns.
Encrypted strings are used throughout the malware to complicate analysis efforts. The C2 server was offline during the researchers' investigation, but static analysis of the loader suggests it is designed to retrieve a second-stage payload upon successful communication. The observed telemetry indicates that while overall Grandoreiro activity has not reached its previous peak, the continued evolution and adaptation of its campaigns demonstrate that the threat actor remains resilient and active.