Close Menu
  • Home
  • Lifestyle
  • Tech
  • Travel
  • Review
  • About
  • Contact
What's Hot

Pasko sa Baryo Gives Free Entry with GCash Transactions

November 14, 2025

Friendsgiving at SM Malls in the East Metro

November 14, 2025

SpongeBob Movie Search for Squarepants Releases New Trailer

November 14, 2025
Facebook X (Twitter) Instagram
Manila Republic
  • Home
  • Lifestyle
  • Tech
  • Travel
  • Review
  • About
  • Contact
Manila Republic
Home»Tech»Kaspersky uncovers new Grandoreiro light variant
Tech

Kaspersky uncovers new Grandoreiro light variant

Team Manila RepublicBy Team Manila RepublicOctober 27, 2024No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Despite the arrest of important operators in early 2024, Grandoreiro continues to be used by its partners in new campaigns. Kaspersky Global Research and Analysis team (GReAT) has discovered a new light version focused on Mexico targeting around 30 banks. These findings are to be highlighted at the Security Analyst Summit (SAS) 2024. Remaining one of the most active threats globally, Grandoreiro accounts for around five percent of banking trojan attacks this year.  Mexico is one of the most targeted countries by Grandoreiro variants, including the new light version, seeing 51,000 recorded incidents this year.

After assisting an INTERPOL-coordinated action, which has led to Brazilian authorities arresting operators behind a Grandoreiro banking trojan operation, Kaspersky discovered that the group’s codebase has been split into lighter, fragmented versions of the trojan, to continue its attacks. Recent analysis has identified a specific light version focused primarily on Mexico, which has been used to target approximately 30 financial institutions. The creators likely have access to the source code and are launching new campaigns using the simplified legacy malware.

“All the recent developments underscore the evolving nature of the threat. Fragmented and lighter versions may represent a trend that could extend beyond Mexico and into other regions, including beyond Latin America. However, we believe that only some trusted affiliates have access to the malware source code to develop such lighter versions. Grandoreiro operates differently from the traditional ‘Malware-as-a-Service’ model we are accustomed to. You won’t find announcements on underground forums selling the Grandoreiro package; instead, access to it appears to be limited,” explains Fabio Assolini, head of the Latin American (GReAT) at Kaspersky.

Multiple variants of Grandoreiro, including the new light version and the primary malware, accounted for approximately five percent of global banking trojan attacks detected by Kaspersky in 2024, making it one of the most active threats worldwide. Kaspersky has also analyzed the newer samples of the primary Grandoreiro from 2024, and observed new tactics. It records mouse activity to mimic real user patterns, aiming to evade detection by machine learning-based security systems that analyze behavior. By replaying natural mouse movements, the malware aims to trick anti-fraud tools into seeing the activity as legitimate.

Additionally, Grandoreiro has adopted a cryptographic technique known as Ciphertext Stealing (CTS), which Kaspersky has never seen being used in malware. In this case, its aim is to encrypt the malicious code strings. “Grandoreiro has a large and complex structure, which would make it easier for security tools or analysts to detect if its strings were not encrypted. This is likely why they introduced this new technique – to complicate the detection and analysis of their attacks,” Fabio Assolini elaborated.

Kaspersky data indicates Grandoreiro has been active since 2016. In 2024, the threat targets more than 1,500 financial institutions and 276 cryptocurrency wallets across 45 countries and territories, lastly adding Asia and Africa to the list of its targets, making it a truly global financial threat.

Read more on Securelist. The comprehensive Grandoreiro analysis and overview is to be presented by GReAT at Kaspersky’s sixteenth Security Analyst Summit (SAS), which takes place from October 22-25, 2024, in Bali.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Team Manila Republic

    Related Posts

    LG DualCool Partners App Simplifies Dealer Workflows and Strengthens Partnerships

    November 12, 2025

    uHoo Caeli Smart Air Monitor Redefines Indoor Wellness

    November 11, 2025

    Deck the Halls with Samsung Bespoke AI Holiday Deals

    November 11, 2025
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    Pasko sa Baryo Gives Free Entry with GCash Transactions

    November 14, 2025

    Friendsgiving at SM Malls in the East Metro

    November 14, 2025

    SpongeBob Movie Search for Squarepants Releases New Trailer

    November 14, 2025

    Wuthering Heights Movie 2026 Brings a New Love Story to Cinemas

    November 14, 2025

    SHARP Refrigerator: Your Ultimate Holiday Storage Companion

    November 14, 2025
    Advertisement
    Don't Miss

    Pasko sa Baryo Gives Free Entry with GCash Transactions

    GabrielNovember 14, 2025

    Pasko sa Baryo GCash Promo Offers Free Entry and Raffle Perks Pasko sa Baryo brings…

    Friendsgiving at SM Malls in the East Metro

    November 14, 2025

    SpongeBob Movie Search for Squarepants Releases New Trailer

    November 14, 2025

    Wuthering Heights Movie 2026 Brings a New Love Story to Cinemas

    November 14, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    © 2025 ThemeSphere. Designed by ThemeSphere.
    • Home
    • Lifestyle
    • Tech
    • Travel
    • Review
    • About
    • Contact

    Type above and press Enter to search. Press Esc to cancel.