Grandoreiro banking trojan returns to hit Mexico and Peru

An email that looks like an unpaid invoice, with a ZIP file attached. That is the whole opening move in a renewed Grandoreiro campaign that Colombia's national cyber emergency response centre, colCERT, has now rated a high risk across Latin America. Its alert names Mexico, Peru and Argentina as the countries carrying the sharpest exposure, alongside others in the region.

Grandoreiro is a banking trojan: malware built to sit on a victim's computer and steal the credentials and session access needed to move money out of their bank account. It has been running since at least 2016, it is written in Delphi, and it has proved remarkably hard to kill. Law enforcement disrupted the operation in 2024. The code came back lighter and more evasive rather than disappearing.

The target list moved, and Brazil came off it

colCERT's alert points to a strategic shift rather than a simple relaunch. The variant observed between May and June 2026 stopped operating against Brazil and Portugal, the trojan's traditional hunting grounds, and concentrated its capacity on Mexico, the rest of Latin America and Spain instead. For defenders in the region that reordering matters more than the malware's age: organisations that treated Grandoreiro as somebody else's problem are now inside the target set.

A legitimate app carries the payload in

The delivery chain starts with malicious spam carrying a ZIP attachment disguised as an invoice, one example named FacBH22DC0608_RevMQKSAC.zip. The infection then abuses a legitimate application, the Duplicate Files Finder utility, through DLL side-loading. That technique works by placing a malicious library where a trusted program will load it, so the harmful code runs inside a signed, expected process and inherits its good reputation with security tools. It is a cheap way to get past defences that decide what to trust by looking at which program is running rather than what that program just loaded.

What to tell staff, and what to watch

colCERT's alert is published TLP:CLEAR, meaning it can be shared freely, and the practical guidance is unglamorous. Treat unexpected invoice attachments as hostile, particularly compressed ones, and give finance and accounts payable teams a route to report them that is faster than opening them. On the technical side, watch for a trusted utility loading a library from a user-writable directory, which is the observable behaviour that DLL side-loading produces regardless of which application is abused this month.

The alert does not publish file hashes or network indicators, so there is no indicator block to lift from it. Read colCERT's original alert for its full text. The wider regional picture is not encouraging either: Mexican organisations have also been appearing on ransomware leak sites at an unusual rate this month, and country context sits on our Colombia profile.

A ten-year-old trojan that survived a police takedown and then picked a new set of countries is not a legacy threat. It is an operation choosing where the returns are better.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions