ATT&CKSoftwareGrandoreiro

Grandoreiro

S0531

Malware.View on attack.mitre.org

About this malware

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.

Techniques used43

Procedure examples43

TechniqueProcedure example
T1010
Application Window Discovery

Grandoreiro can identify installed security tools based on window names.

T1016
System Network Configuration Discovery

Grandoreiro can determine the IP and physical location of the compromised host via IPinfo.

T1027.001
Binary Padding

Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size.

T1027.011
Fileless Storage

Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.

T1027.013
Encrypted/Encoded File

The Grandoreiro payload has been delivered encrypted with a custom XOR-based algorithm and also as a base64-encoded ZIP file.

T1033
System Owner/User Discovery

Grandoreiro can collect the username from the victim's machine.

T1036.005
Match Legitimate Resource Name or Location

Grandoreiro has named malicious browser extensions and update files to appear legitimate.

T1041
Exfiltration Over C2 Channel

Grandoreiro can send data it retrieves to the C2 server.

T1056.001
Keylogging

Grandoreiro can log keystrokes on the victim's machine.

T1057
Process Discovery

Grandoreiro can identify installed security tools based on process names.

T1059.005
Visual Basic

Grandoreiro can use VBScript to execute malicious code.

T1070.004
File Deletion

Grandoreiro can delete .LNK files created in the Startup folder.

T1071.001
Web Protocols

Grandoreiro has the ability to use HTTP in C2 communications.

T1082
System Information Discovery

Grandoreiro can collect the computer name and OS version from a compromised host.

T1087.003
Email Account

Grandoreiro can parse Outlook .pst files to extract e-mail addresses.

View all 43 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. ESET Grandoreiro April 2020 Open source
    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.
  2. Securelist Brazilian Banking Malware July 2020 Open source
    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.