HomeSecurityGrandoreiro malware: What is it and how does it work?

Grandoreiro malware: What is it and how does it work?

One of the new types of malware that has caught the attention of researchers is the Grandoreiro malware. Below we will go into detail about what it is, how it works, and how you can avoid falling victim to it.

What is Grandoreiro?

Written in the Delphi programming language, Grandoreiro is a banking overlay Trojan that has earned a name for its ability to steal money from online banking customers and has been active since at least 2017.

Remote banking Trojans overlays are designed to allow attackers to “take over” devices. This often involves displaying (full-screen) image overlays on the computers when they access their online banking account. Although this type of banking Trojan has not been widely publicized, it can be quite destructive, as it allows attackers to transfer funds from a victim to the attacker during the victim’s online banking session.

In the case of Grandoreiro, every time a user on an infected computer visits a targeted banking website, the attackers will begin making fraudulent transfers from the account the user was logged into.

Grandoreiro malware

How does Grandoreiro work?

Grandoreiro enters the first stage of infection when the user clicks on the malicious URL and the loader is downloaded. The next stage of infection involves retrieving the Grandoreiro payload via a URL written in the loader code.

Once the infection phases are complete, Grandoreiro collects the following information from the infected computer:

  • User name
  • Computer name
  • Bit number (32 or 64) and operating system version
  • List of installed AV or antivirus

Grandoreiro has credential stealing capabilities in some versions of Google Chrome. It will create a fake Google Chrome extension called Edit This Cookie, which appears to support Grandoreiro's credential stealing capabilities, grabbing user cookies to steal user information and allowing the attacker to "steal" the user's active session. This means that the attacker does not need to control the computer from this point.

Whenever a user of an infected computer visits a targeted banking website, Grandoreiro will invade the account and make fraudulent transfers to accounts controlled by the hackers. While this is the focus of the attack, Grandoreiro has other capabilities and tools, such as keylogging, self-update, keyboard and mouse emulation, and a backdoor with extensive capabilities.

How to prevent Grandoreiro

Grandoreiro malware can be avoided with the classic prevention methods that we have mentioned to you many times. Do not click on videos on suspicious websites. If you do not know who the sender of an email is, do not download attachments or click on links from unknown URLs. If in doubt, contact the alleged sender through a different channel and confirm that it is them.

Many common antiviruses can detect and/or stop malware from infecting computer . While this may be the case, the first and best line of defense against malware like Grandoreiro is a cybersecurity-aware user.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS