Post #4501348
2026-08-11 14:07 UTC
Over the past days, active #malspam campaigns targeting LatAm users ๐ฆ๐ท๐ง๐ท๐ฒ๐ฝ have been delivering the Grandoreiro banking trojan ๐ฆ๐ฐ
๐ง Email โ ๐ JS file โ ๐ Fake PDF download
Final payload is hosted on MediaFire ๐ฅ free file hosting
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent ๐ฅ๏ธโคต๏ธ
User-Agent: Embarcadero URI Client/1.0
๐ Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com ๐
๐ก Grandoreiro botnet C2s hosted at AWS:
54.80.154.193
54.91.129.132
54.91.223.28
๐ Payloads URLs:
https://urlhaus.abuse.ch/browse/tag/Grandoreiro/
๐ Malware samples:
https://bazaar.abuse.ch/browse/signature/Grandoreiro/
๐ฆ Relevant IOCs are available on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.grandoreiro/
Replies (0)
No replies.