LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0531: Grandoreiro

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.[1][2]

EnterpriseS0531MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S0531: Grandoreiro describes [Grandoreiro](https://attack.mitre.org/software/S0531) is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. [Grandoreiro](https://attack.mitre.org/software/S0531) has confirmed victims in Brazil, Mexico, Portugal, and Spain.(Citation: Securelist Brazilian Banking Malware July 2020)(Citation: ESET Grandoreiro April 2020)

Executive priority

S0531: Grandoreiro is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S0531: Grandoreiro by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S0531: Grandoreiro appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Grandoreiro

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

43 rows
DomainIDNameRelationship / procedure
EnterpriseT1059.005Visual BasicSub-technique

Grandoreiro can use VBScript to execute malicious code.[1][2]

EnterpriseT1204.001Malicious LinkSub-technique

Grandoreiro has used malicious links to gain execution on victim machines.CitationIBM Grandoreiro April 2020[2]

EnterpriseT1057Process Discovery

Grandoreiro can identify installed security tools based on process names.[2]

EnterpriseT1547.009Shortcut ModificationSub-technique

Grandoreiro can write or modify browser shortcuts to enable launching of malicious browser extensions.CitationIBM Grandoreiro April 2020

EnterpriseT1539Steal Web Session Cookie

Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device.CitationIBM Grandoreiro April 2020

EnterpriseT1105Ingress Tool Transfer

Grandoreiro can download its second stage from a hardcoded URL within the loader's code.CitationIBM Grandoreiro April 2020[2]

EnterpriseT1573.002Asymmetric CryptographySub-technique

Grandoreiro can use SSL in C2 communication.CitationIBM Grandoreiro April 2020

EnterpriseT1102.001Dead Drop ResolverSub-technique

Grandoreiro can obtain C2 information from Google Docs.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Grandoreiro has named malicious browser extensions and update files to appear legitimate.CitationIBM Grandoreiro April 2020[2]

EnterpriseT1112Modify Registry

Grandoreiro can modify the Registry to store its configuration at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.[2]

EnterpriseT1102.002Bidirectional CommunicationSub-technique

Grandoreiro can utilize web services including Google sites to send and receive C2 data.CitationIBM Grandoreiro April 2020[2]

EnterpriseT1041Exfiltration Over C2 Channel

Grandoreiro can send data it retrieves to the C2 server.[2]

EnterpriseT1222.001Windows PermissionsSub-technique

Grandoreiro can modify the binary ACL to prevent security tools from running.[2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

The Grandoreiro payload has been delivered encrypted with a custom XOR-based algorithm and also as a base64-encoded ZIP file.[1][2][2]

EnterpriseT1124System Time Discovery

Grandoreiro can determine the time on the victim machine via IPinfo.[2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Grandoreiro can use run keys and create link files in the startup folder for persistence.CitationIBM Grandoreiro April 2020[2]

EnterpriseT1204.002Malicious FileSub-technique

Grandoreiro has infected victims via malicious attachments.CitationIBM Grandoreiro April 2020

EnterpriseT1033System Owner/User Discovery

Grandoreiro can collect the username from the victim's machine.[2]

EnterpriseT1010Application Window Discovery

Grandoreiro can identify installed security tools based on window names.[2]

EnterpriseT1027.011Fileless StorageSub-technique

Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including %USERNAME% and ToolTech-RM.[2]

EnterpriseT1082System Information Discovery

Grandoreiro can collect the computer name and OS version from a compromised host.[2]

EnterpriseT1027.001Binary PaddingSub-technique

Grandoreiro has added BMP images to the resources section of its Portable Executable (PE) file increasing each binary to at least 300MB in size.[2]

EnterpriseT1218.007MsiexecSub-technique

Grandoreiro can use MSI files to execute DLLs.[1]

EnterpriseT1518.001Security Software DiscoverySub-technique

Grandoreiro can list installed security products including the Trusteer and Diebold Warsaw GAS Tecnologia online banking protections.[2][2]

EnterpriseT1185Browser Session Hijacking

Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.[1]CitationIBM Grandoreiro April 2020[2]

EnterpriseT1056.001KeyloggingSub-technique

Grandoreiro can log keystrokes on the victim's machine.[2]

EnterpriseT1070.004File DeletionSub-technique

Grandoreiro can delete .LNK files created in the Startup folder.[2]

EnterpriseT1497.001System ChecksSub-technique

Grandoreiro can detect VMWare via its I/O port and Virtual PC via the vpcext instruction.[2]

EnterpriseT1685Disable or Modify Tools

Grandoreiro can hook APIs, kill processes, break file system paths, and change ACLs to prevent security tools from running.[2]

EnterpriseT1115Clipboard Data

Grandoreiro can capture clipboard data from a compromised host.CitationIBM Grandoreiro April 2020

EnterpriseT1176.001Browser ExtensionsSub-technique

Grandoreiro can use malicious browser extensions to steal cookies and other user information.CitationIBM Grandoreiro April 2020

EnterpriseT1140Deobfuscate/Decode Files or Information

Grandoreiro can decrypt its encrypted internal strings.[2]

EnterpriseT1189Drive-by Compromise

Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer.[1]CitationIBM Grandoreiro April 2020

EnterpriseT1686.002Network Device FirewallSub-technique

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level. [2]

EnterpriseT1548.002Bypass User Account ControlSub-technique

Grandoreiro can bypass UAC by registering as the default handler for .MSC files.[2]

EnterpriseT1016System Network Configuration Discovery

Grandoreiro can determine the IP and physical location of the compromised host via IPinfo.[2]

EnterpriseT1106Native API

Grandoreiro can execute through the WinExec API.[2]

EnterpriseT1568.002Domain Generation AlgorithmsSub-technique

Grandoreiro can use a DGA for hiding C2 addresses, including use of an algorithm with a user-specific key that changes daily.[1][2]

EnterpriseT1071.001Web ProtocolsSub-technique

Grandoreiro has the ability to use HTTP in C2 communications.CitationIBM Grandoreiro April 2020[2]

EnterpriseT1566.002Spearphishing LinkSub-technique

Grandoreiro has been spread via malicious links embedded in e-mails.CitationIBM Grandoreiro April 2020[2]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Grandoreiro can steal cookie data and credentials from Google Chrome.CitationIBM Grandoreiro April 2020[2]

EnterpriseT1686Disable or Modify System Firewall

Grandoreiro can block the Deibold Warsaw GAS Tecnologia security tool at the firewall level.[2]

EnterpriseT1087.003Email AccountSub-technique

Grandoreiro can parse Outlook .pst files to extract e-mail addresses.[2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.2
Created
Modified
Raw hash
a50e89f57a9de045...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.2Current bundlea50e89f57a9d…
19.11.2Older bundlea50e89f57a9d…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Securelist Brazilian Banking Malware July 2020

    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

    Open source URL
  2. [2]
    ESET Grandoreiro April 2020

    ESET. (2020, April 28). Grandoreiro: How engorged can an EXE get?. Retrieved November 13, 2020.

    Open source URL
  3. [3]
    mitre-attackS0531
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.