Tech and Teen
  • Technology
  • Teen
  • Entertainment
  • Sports
  • Politics
  • Business
  • World
  • Multimedia
  • IT HOT
  • Blog
  • Technology
  • Teen
  • Entertainment
  • Sports
  • Politics
  • Business
  • World
  • Multimedia
  • IT HOT
  • Blog

Tech and Teen

  • Technology
  • Teen
  • Entertainment
  • Sports
  • Politics
  • Business
  • World
  • Multimedia
  • IT HOT
  • Blog

Kaspersky uncovers new Grandoreiro light variant

by Tech and Teen October 23, 2024
written by Tech and Teen October 23, 2024
Kaspersky uncovers new Grandoreiro light variant

Despite the arrest of important operators in early 2024, Grandoreiro continues to be used by its partners in new campaigns. Kaspersky Global Research and Analysis team (GReAT) has discovered a new light version focused on Mexico targeting around 30 banks. These findings are to be highlighted at the Security Analyst Summit (SAS) 2024. Remaining one of the most active threats globally and targeting users of more than 1,700 banks, Grandoreiro variants account for around five percent of banking trojan attacks this year. Mexico is one of the most targeted countries by various Grandoreiro strains, including the new light version, seeing 51,000 recorded incidents this year.

After assisting an INTERPOL-coordinated action, which has led to Brazilian authorities arresting operators behind a Grandoreiro banking trojan operation, Kaspersky discovered that the group’s codebase has been split into lighter, fragmented versions of the trojan, to continue its attacks. Recent analysis has identified a specific light version focused primarily on Mexico, which has been used to target approximately 30 financial institutions. The creators likely have access to the source code and are launching new campaigns using the simplified legacy malware.

“All the recent developments underscore the evolving nature of the threat. Fragmented and lighter versions may represent a trend that could extend beyond Mexico and into other regions, including beyond Latin America. However, we believe that only some trusted affiliates have access to the malware source code to develop such lighter versions. Grandoreiro operates differently from the traditional ‘Malware-as-a-Service’ model we are accustomed to. You won’t find announcements on underground forums selling the Grandoreiro package; instead, access to it appears to be limited,” explains Fabio Assolini, head of the Latin American (GReAT) at Kaspersky.

Multiple variants of Grandoreiro, including the new light version and the primary malware, accounted for approximately five percent of global banking trojan attacks detected by Kaspersky in 2024, making it one of the most active threats worldwide. Kaspersky has also analyzed the newer samples of the primary Grandoreiro from 2024, and observed new tactics. It records mouse activity to mimic real user patterns, aiming to evade detection by machine learning-based security systems that analyze behavior. By replaying natural mouse movements, the malware aims to trick anti-fraud tools into seeing the activity as legitimate.
Additionally, Grandoreiro has adopted a cryptographic technique known as Ciphertext Stealing (CTS), which Kaspersky has never seen being used in malware. In this case, its aim is to encrypt the malicious code strings. “Grandoreiro has a large and complex structure, which would make it easier for security tools or analysts to detect if its strings were not encrypted. This is likely why they introduced this new technique – to complicate the detection and analysis of their attacks,” Fabio Assolini elaborated.
Kaspersky data indicates Grandoreiro has been active since 2016. In 2024, the threat targets more than 1,700 financial institutions and 276 cryptocurrency wallets across 45 countries and territories, lastly adding Asia and Africa to the list of its targets, making it a truly global financial threat.

 

 

Kaspersky
0 comment
0
FacebookTwitterGoogle +PinterestLinkedinWhatsapp
previous post
Enjoy exciting cashback on Samsung’s premium D-Series 4K AI TVs
next post
Banglalink Introduces Exciting Value Back Offers on iPhone 16 Series

related posts

Infinix’s charging innovation inspired youth at VR cricket...

July 5, 2024

Grameenphone Partners with Mobileum to Enhance Customer Experience...

August 15, 2024

Visa celebrates Ramadan and other Festivities with Exciting...

March 12, 2025

Winners of ‘Ramadan Deals’ awarded with prizes by...

June 12, 2019

Grameenphone Commemorates International Sign Language Day to Promote...

October 3, 2024

Meta launches #SheMeansBusiness to empower Bangladeshi women entrepreneurs

April 10, 2022

Double the joy of Eid with Samsung’s special...

March 12, 2025

realme C65 available nationwide with No.1 quality

May 15, 2024

Jovago offers budget accommodation for Bikers

July 30, 2018

BMW electrifies Bangladesh and launches BMW iPerformance vehicles

November 3, 2018

OPPO A9 2020: The gaming beast with 8GB...

September 29, 2019

Goldberg’s new flagship mobile hits market

July 30, 2018

Leave a Comment Cancel Reply

Save my name, email, and website in this browser for the next time I comment.


The reCAPTCHA verification period has expired. Please reload the page.

  • Technology
  • Teen
  • Business
  • Privacy Policy
  • Multimedia
  • Sports
  • Entertainments
  • About Us

About Us

Techandteen is the vibrant tech news site in Bangladesh. It provides new tech news and latest tech news and reviews for teenagers. As a tech blog techandteen is also popular tech site and best tech site in Dhaka. We accept Guest Posts and paid Promotions.

Email : shiningbd2014@gmail.com

Dhaka, Bangladesh

Phone : +88 00 5555

Popular Posts

  • 1

    Grab these Revolutionary vivo Smartphones: Available in Stores And e-Commerce Sites Now

  • 2

    HUAWEI P30 and P30 Pro Review, Pricing and Availability

  • 3

    ASUS Announces 5.5-inch ZenFone 3 Max in Bangladesh

Follow us on Facebook

Facebook
  • Technology
  • Teen
  • Business
  • Privacy Policy
  • Multimedia
  • Sports
  • Entertainments
  • About Us

@ 2018-2025 - Tech and Teen. All Right Reserved.
Developed By: Deshi Hosting, Amjhupi, Meherpur.