×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET Research reports: Latin American banking Trojans spread to Europe

Customer Press Room

ESET Research reports: Latin American banking Trojans spread to Europe

by Grandangolo Communications / Wednesday, 22 December 2021 / Published in Eset

Latin American banking Trojans are an ever-evolving threat, and ESET has recently observed some of their largest campaigns to date. They mainly affect Brazil, Spain and Mexico. Mekotio and Grandoreiro have expanded into Europe, also targeting Italy, France and Belgium.

ESET, a global leader in the cybersecurity market, has concluded its investigation dedicated to debunking Latin American banking Trojans that began in August 2019. Since then, it has examined the most active ones, namely Vavals, Casbaneiro, Mispadu, Guildma, Grandoreiro, Mekotio, Vadokrist, Ousaban e Numando, which share many characteristics and behaviors with each other. Overall, ESET has identified a dozen different malware families, most of which are still active. The most important discovery that occurred during this investigation is the expansion of Mekotio and Grandoreiro in Europe, especially in Spain; this is accompanied by occasional small campaigns that have been observed by ESET researchers in Italy, France and Belgium. Since they have expanded into Europe, and this has happened increasingly in recent months, Latin American banking Trojans have gained more and more attention from both researchers and police forces

ESET telemetry shows a surprising increase in the reach of Ousaban, Grandoreiro and Casbaneiro in recent months, suggesting that the threat actors behind these malware families are determined to continue their malicious actions against users in the target countries.

It has been found that these campaigns always come in waves and more than 90% of them are distributed through spam and are typically targeted at a ZIP archive or MSI installer. A campaign usually lasts a maximum of one week.

"Brazil is still the most targeted country, followed by Spain and Mexico. Since 2020, Grandoreiro and Mekotio have expanded into Europe – mainly Spain. What started with several smaller campaigns, probably to test new territory, has evolved into something much bigger. In fact, in August and September 2021, Grandoreiro launched its largest campaign yet and targeted Spain," he explained Jakub Souček, researcher at ESET leading investigations into Latin American banking Trojans.

In June 2021 the Spanish law enforcement agencies have arrested 16 people linked to Mekotio and Grandoreiro. The police specified that almost 300,000 euros were stolen, but that it was possible to block the transfer of a total of 3.5 million euros. Correlating this arrest with the activity of Latin American banking Trojans in Spain, it would appear that the arrested people were linked to Mekotio, although ESET detected further movements.

Latin American banking Trojans tend to change quickly. In the early days of monitoring ESET, some of them added or changed key features even several times a month. Today they still change very often, but the core seems to remain mostly intact. Precisely because of a partially stabilized development, ESET believes that operators are now focusing on improving distribution.

“Latin American banking Trojans require many conditions to be met for the attack to be successful,” says Souček. "Potential victims have to follow the necessary steps to install the malware on their machines; they have to visit a targeted website and log in to their accounts. On the other hand, the operators have to react to this situation by manually guiding the malware to display the fake pop-up window and take control of the victim's machine."

During this series of searches, several Latin American banking Trojans became inactive, most notably Krachulka, Lokorrito, and Zumanek. Recently, ESET researchers also discovered window, a new Latin American banking trojan. In the future, ESET plans to expand some of these banking Trojans to the Android platform.

More technical details on Latin American banking Trojans, at this link “Latin America's Dirty Dozen: From Amavaldo to Zumanek” su WeLiveSecurity.

Tagged under: Eset, trojan

About Grandangolo Communications

What you can read next

ESET expands its Corporate Security with Endpoint Antivirus for Linux
ESET reconfirms itself as 'Champion' in the Canalys Cybersecurity Leadership Matrix of 2021
ESET announces the global FinTech research, which analyzes user behaviors regarding cybersecurity

Customer Press Room

  • ESET releases SMB IT Readiness Index 2026, highlighting growing confidence but also concerns about AI technologies

    The majority of SMEs declare themselves optimistic...
  • ESET discovers the new arsenal of Webworm, a pro-Chinese APT active against European governments

    ESET Research analyzed recent activity…
  • Arrow Electronics expands distribution agreement with Veeam in EMEA

    Arrow Electronics, a global supplier of technology...
  • ESET Research APT Report: China-aligned groups spy on Venezuela and Gulf, targeting AI robotics in South Korea

    L’ultimo APT Activity Report di ESET Research t...
  • ESET accelerates AI innovation with investments aimed at managing a rapidly expanding attack surface

    ESET announces a 40 million investment ...

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP