Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

A Second Nation Just Built a State Bitcoin Mining Pool — Oman’s Omanhash.om Redraws the Map

June 17, 2026

South Korea arrests 23 over USDT laundering for Cambodian fraud network

June 17, 2026

UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows

June 17, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New Grandoreiro Malware Variant Targets Spain
New Grandoreiro Malware Variant Targets Spain
Security and Privacy

New Grandoreiro Malware Variant Targets Spain

October 24, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Cybersecurity experts at Proofpoint have identified a new variant of the Grandoreiro malware, previously known for targeting victims in Brazil and Mexico. This latest version of Grandoreiro, attributed to the threat actor TA2725, has expanded its reach to target banks in Spain as well. 

Writing in an advisory published today, the researchers said they recently noticed an unusual increase in the frequency and volume of malicious activity targeting Spain, a departure from the malware’s traditional focus on Portuguese and Spanish speakers in the Americas.

According to Proofpoint, Brazil is among the most highly targeted countries for information stealers and other malware. Its widespread use of online banking provides opportunities for threat actors to exploit unsuspecting victims.

“The Brazilian cyber threat landscape has changed rapidly over the last several years, becoming more complicated and diverse,” explained Proofpoint researcher Jared Peck. “More people than ever are online in the country, meaning the potential victim base has increased.”

The Grandoreiro malware family, commonly written in Delphi, has been active for years, with various strains like Javali, Casabeniero, Mekotio and Grandoreiro itself. The malware is capable of data theft through keyloggers and screen-grabbers and can steal bank login information from overlays on banking websites. Typically delivered via email lures, it executes a malicious file that contacts a command-and-control (C2) server.

Read more on Grandoreiro: Researchers Spot Banking Trojan Using #COVID19 Crisis to Attack Users

Until recently, Grandoreiro had primarily targeted banks in Brazil and Mexico. However, recent campaigns revealed that the malware’s bank credential-stealing overlays have expanded to include banks in Spain. This means that TA2725 can now simultaneously target victims in both Spain and Mexico without modifying the malware.

See also  Malvertising Campaign Delivers Millions of Bad Ads

TA2725, known for using Brazilian banking malware and phishing, has been observed targeting credentials for banks in Brazil and Mexico, along with consumer credentials and payment information for Netflix and Amazon accounts.

“Given the rapid malware development and tenacity of threat actors in Latin America and South America, we expect to see an increase in targets of opportunity outside that region who share a common language,” Peck wrote in the advisory.

“As the global supply chain continues to evolve and rely on suppliers around the world, the targeting of organizations outside of a company’s normal service region will continue to be an increasing threat to all organizations worldwide.”

Source link

Grandoreiro Malware Spain Targets Variant
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Congress Targets Crypto ATMs After Americans Lose $333M to Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

FBI Warns Courier Cash Pickups Are Driving Crypto Scams

June 16, 2026

Ethereum Research Proposal Targets Post-Quantum Wallet Security At Low Gas Cost

June 16, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Kraken may soon launch stock trading services for U.S. and U.K. markets: Report

September 27, 2023

US Lawmakers Demand Answers From Gary Gensler on SEC’s Position That Crypto Airdrops Are Securities Transactions

September 19, 2024

NFT Market Sees 20% Drop in Weekly Sales After a Few Weeks of Gains

June 15, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

A Second Nation Just Built a State Bitcoin Mining Pool — Oman’s Omanhash.om Redraws the Map

June 17, 2026

South Korea arrests 23 over USDT laundering for Cambodian fraud network

June 17, 2026

UK Sanctions HTX Over Alleged $1.5 Billion Russia-Linked Crypto Flows

June 17, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$66,076.000.59%
  • ethereumEthereum(ETH)$1,776.360.07%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$607.280.31%
  • rippleXRP(XRP)$1.220.65%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$74.221.36%
  • tronTRON(TRX)$0.3218151.50%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.53%
  • HyperliquidHyperliquid(HYPE)$76.132.49%