Briefing

Banking Trojan Campaigns Targeting Latin America and Europe with Grandoreiro and BTMOB

security
by [email protected] (The Hacker News) ·

Patch: Update antivirus signatures to block Grandoreiro and BTMOB on Windows and Android endpoints, and monitor for banking trojan activity in Spain, Portugal, Mexico, and Brazil.

What to do now

Patch: Update antivirus signatures to block Grandoreiro and BTMOB on Windows and Android endpoints, and monitor for banking trojan activity in Spain, Portugal, Mexico, and Brazil.

Summary

WatchGuard and ESET have uncovered two coordinated banking trojan campaigns that target Windows and Android devices in Latin America and Europe. The Windows trojan, named Grandoreiro, is designed to steal banking credentials from victims in Spain, Portugal, and Mexico. The Android variant, BTMOB, infects mobile users in Brazil and harvests banking information from their devices. Both malware families use sophisticated delivery mechanisms, including malicious links and compromised websites, to bypass endpoint protection. The campaigns specifically single out corporate targets, indicating a targeted threat actor with financial motives. Security teams should update antivirus signatures for Grandoreiro and BTMOB and monitor for suspicious banking activity in the affected regions. The findings highlight the need for continuous threat intelligence and region‑specific monitoring. Organizations in the targeted countries should also review their mobile device management policies.

Key changes

  • Grandoreiro targets Windows banking credentials in Spain, Portugal, Mexico
  • BTMOB targets Android banking credentials in Brazil
  • WatchGuard and ESET identified the campaigns
  • Both use malicious links and compromised websites for delivery
  • The campaigns specifically target corporate accounts
  • Security teams should update signatures and monitor for suspicious activity
  • The threat underscores the need for region‑specific monitoring

Affects

enterprise

Source angles · 2 perspectives

The Hacker News
Independent angle

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

Open
Bleeping Computer
Independent angle

BTMOB Android malware service generates custom phishing payloads

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting