Affected Systems
Windows and Android devices in Latin America (Brazil, Mexico) and Europe (Spain, Portugal). Grandoreiro targets Windows systems at companies; BTMOB RAT targets Android mobile users in Brazil.
Exploitation Status
Active campaign. Grandoreiro and BTMOB RAT are being actively deployed in coordinated banking trojan operations identified by WatchGuard and ESET.
Business Impact
Organizations in affected regions face credential theft, unauthorized banking transactions, and potential financial fraud. Mobile users risk account compromise through Android RAT. No CVE assigned; threat actor-driven campaign rather than vulnerability exploitation.
Urgency
đźź Within 24 hours
Recommended Actions
- Deploy endpoint detection rules for Grandoreiro and BTMOB RAT indicators published by WatchGuard and ESET
- Block known C2 domains and IPs associated with these campaigns at perimeter firewalls and DNS filters
- Enforce mobile device management (MDM) policies restricting sideloading on Android devices in corporate environments
- Monitor Windows event logs and Android device logs for suspicious process execution and network connections to unknown external IPs
- Conduct user awareness training focused on phishing emails and malicious app installations targeting banking credentials
---
# Geopolitical Context
Geopolitical Context
The coordinated campaigns reflect the persistent threat posed by financially motivated cybercrime targeting Spanish and Portuguese-speaking economies. Grandoreiro, a well-established Latin American banking trojan, has expanded its operational scope from its traditional Brazilian origins to encompass Iberian Peninsula targets, indicating the maturation of regional cybercrime ecosystems. The simultaneous deployment of BTMOB RAT against Brazilian mobile users suggests a diversified approach by threat actors seeking to exploit both desktop and mobile banking infrastructure. These campaigns underscore the linguistic and cultural targeting strategies employed by cybercriminal groups, which leverage shared language and banking practices across the Lusophone and Hispanophone worlds to maximize operational efficiency. The financial services sector remains a priority target due to direct monetization opportunities, and the cross-continental nature of these operations demonstrates the increasingly borderless character of organized cybercrime.
State Actor Alignment
No state actor attribution has been reported for these campaigns. The activity appears consistent with financially motivated cybercrime rather than state-sponsored operations. Brazilian law enforcement has historically pursued Grandoreiro operators, and international cooperation between Spanish, Portuguese, Mexican, and Brazilian authorities may be relevant to disruption efforts. These campaigns do not appear to align with known state cyber programs, though the technical infrastructure and operational security of such groups can occasionally intersect with state-tolerated cybercrime environments in certain jurisdictions.
Business Impacty pro region
For Europe, the targeting of Spain and Portugal represents a continuation of Latin American banking trojan expansion into European markets, particularly those with linguistic and economic ties to Latin America. Financial institutions in these countries face elevated risk from threat actors with deep operational experience in the region. In Latin America, the campaigns reinforce Brazil and Mexico's positions as high-priority targets for banking malware, reflecting their large digital banking user bases and evolving financial technology sectors. The dual-platform approach—targeting both Windows desktop and Android mobile devices—signals an adaptation to changing consumer banking behaviors across both regions. Financial regulators and cybersecurity agencies in affected countries may need to enhance cross-border information sharing and coordinate defensive measures, particularly given the transnational nature of these threat actors and their infrastructure.
Forecast
If current trends continue, banking trojan operators are likely to maintain focus on Spanish and Portuguese-speaking markets due to linguistic advantages and established infrastructure. Should law enforcement coordination between European and Latin American authorities intensify, disruption operations targeting Grandoreiro and similar malware families may increase in frequency. If mobile banking adoption continues to accelerate in Latin America, mobile-focused threats like BTMOB RAT are likely to proliferate and potentially expand to European targets. Financial institutions in affected regions should anticipate sustained campaigns and may see threat actors adopt more sophisticated evasion techniques if current detection rates improve. If economic conditions in target countries shift significantly, threat actors may adjust geographic priorities or targeting criteria accordingly.
