<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Grandoreiro - Latest News &amp; Reviews</title>
	<atom:link href="https://www.thetechoutlook.com/tag/grandoreiro/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.thetechoutlook.com/tag/grandoreiro/</link>
	<description>Daily Tech News, Interviews, Reviews and Updates</description>
	<lastBuildDate>Sat, 20 Aug 2022 13:07:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://www.thetechoutlook.com/wp-content/uploads/2019/09/cropped-favicon-1-150x150.png</url>
	<title>Grandoreiro - Latest News &amp; Reviews</title>
	<link>https://www.thetechoutlook.com/tag/grandoreiro/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The infamous &#8220;Grandoreiro&#8221; banking trojan used in recent attacks on employees of a chemicals company in Spain</title>
		<link>https://www.thetechoutlook.com/news/security/the-infamous-grandoreiro-banking-trojan-used-in-recent-attacks-on-employees-of-a-chemicals-company-in-spain/</link>
					<comments>https://www.thetechoutlook.com/news/security/the-infamous-grandoreiro-banking-trojan-used-in-recent-attacks-on-employees-of-a-chemicals-company-in-spain/#respond</comments>
		
		<dc:creator><![CDATA[Somya Agrawal]]></dc:creator>
		<pubDate>Sat, 20 Aug 2022 13:07:02 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ Spain]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[Employee]]></category>
		<category><![CDATA[Grandoreiro]]></category>
		<guid isPermaLink="false">https://www.thetechoutlook.com/?p=69382</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820-768x432.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div>
<p>It was discovered that the infamous &#8220;Grandoreiro&#8221; banking trojan was used in recent attacks on employees of a chemicals company in Spain and employees of car and machinery businesses in Mexico. The malware continues to be one of the worst dangers of its kind for Spanish-speaking users, having been active in the wild at least [&#8230;]</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/the-infamous-grandoreiro-banking-trojan-used-in-recent-attacks-on-employees-of-a-chemicals-company-in-spain/">The infamous &#8220;Grandoreiro&#8221; banking trojan used in recent attacks on employees of a chemicals company in Spain</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1200" height="675" src="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820.jpg 1200w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820-300x169.jpg 300w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820-1024x576.jpg 1024w, https://www.thetechoutlook.com/wp-content/uploads/2022/08/Untitled-design-2022-08-20T174601.820-768x432.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" /></div><p>It was discovered that the infamous &#8220;Grandoreiro&#8221; banking trojan was used in recent attacks on employees of a chemicals company in Spain and employees of car and machinery businesses in Mexico. The malware continues to be one of the worst dangers of its kind for Spanish-speaking users, having been active in the wild at least since 2017.</p>
<p>Zscaler researchers first became aware of the current effort in June 2022, and it is still going strong today. The use of a Grandoreiro malware strain with upgraded C2 capability and a number of extra features to avoid detection and anti-analysis is involved. Depending on the victim, the infection chain begins with an email that claims to be from the Mexican Attorney General&#8217;s Office or the Spanish Public Ministry.</p>
<p>Mortgage loan terminations, lawsuit change letters, and state reimbursements are among the topics of communication. An email from the most recent phishing campaign (Zscaler). A ZIP archive is put into a website by means of a link in the email that takes recipients there. To trick the victim into activating the Grandoreiro loader module it contains, this PDF file was presented.</p>
<p>Following that, the loader downloads, extracts, and executes a 9.2MB ZIP file containing a Delphi payload from a remote HTTP file server (&#8220;http://15[.]188[.]63[.]127:36992/zxeTYhO.xml&#8221;). The loader gathers system data at that phase and sends it, along with a list of installed antivirus programs, cryptocurrency wallets, and e-banking applications, to the C2.</p>
<p>The final payload is certified using a certificate that was stolen from ASUSTEK and employs &#8220;binary padding&#8221; to inflate its size to 400MB in order to avoid sandbox examination.<br />
the seal on the certificate for the final payload (Zscaler)</p>
<p>Grandoreiro once went so far as to need the victim to complete a CAPTCHA in order for the attack to be identified, as security analyst Ankit Anubhav pointed out on Twitter.<br />
With the addition of two new Registry keys, Grandoreiro is finally ready to run at system startup and preserve persistence over reboots.</p>
<p>The most recent campaign demonstrates that the operators of Grandoreiro favor carrying out highly targeted attacks over sending out bulk spam to unexpected recipients. The malware&#8217;s continued evolution provides it with better anti-analysis and detection avoidance properties, laying the groundwork for stealthier activities.</p>
<p>The particular goals of the current campaign are not covered in great length in Zscaler&#8217;s report, but Grandoreiro&#8217;s operators have regularly displayed financial reasons, thus it is anticipated that nothing has changed.</p>
<p>The post <a href="https://www.thetechoutlook.com/news/security/the-infamous-grandoreiro-banking-trojan-used-in-recent-attacks-on-employees-of-a-chemicals-company-in-spain/">The infamous &#8220;Grandoreiro&#8221; banking trojan used in recent attacks on employees of a chemicals company in Spain</a> appeared first on <a href="https://www.thetechoutlook.com">The Tech Outlook</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.thetechoutlook.com/news/security/the-infamous-grandoreiro-banking-trojan-used-in-recent-attacks-on-employees-of-a-chemicals-company-in-spain/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
