Malware.View on attack.mitre.org
Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.
| Technique | Procedure example |
|---|---|
| T1010 Application Window Discovery |
Grandoreiro can identify installed security tools based on window names. |
| T1016 System Network Configuration Discovery |
Grandoreiro can determine the IP and physical location of the compromised host via IPinfo. |
| T1027.001 Binary Padding |
Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size. |
| T1027.011 Fileless Storage |
Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including |
| T1027.013 Encrypted/Encoded File |
The Grandoreiro payload has been delivered encrypted with a custom XOR-based algorithm and also as a base64-encoded ZIP file. |
| T1033 System Owner/User Discovery |
Grandoreiro can collect the username from the victim's machine. |
| T1036.005 Match Legitimate Resource Name or Location |
Grandoreiro has named malicious browser extensions and update files to appear legitimate. |
| T1041 Exfiltration Over C2 Channel |
Grandoreiro can send data it retrieves to the C2 server. |
| T1056.001 Keylogging |
Grandoreiro can log keystrokes on the victim's machine. |
| T1057 Process Discovery |
Grandoreiro can identify installed security tools based on process names. |
| T1059.005 Visual Basic |
Grandoreiro can use VBScript to execute malicious code. |
| T1070.004 File Deletion |
Grandoreiro can delete .LNK files created in the Startup folder. |
| T1071.001 Web Protocols |
Grandoreiro has the ability to use HTTP in C2 communications. |
| T1082 System Information Discovery |
Grandoreiro can collect the computer name and OS version from a compromised host. |
| T1087.003 Email Account |
Grandoreiro can parse Outlook .pst files to extract e-mail addresses. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.