Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving banking trojan that employs DLL side-loading techniques and CAPTCHA checks to target financial institutions in Portugal and beyond. Simultaneously, a campaign leveraging the BTMOB remote access trojan (RAT) is targeting Android users in Brazil and Latin America, utilizing phishing and a ready-made app builder to facilitate device compromise.
The ongoing threat landscape includes a persistent banking trojan known as Grandoreiro, which has been active since 2016 and continues to adapt its tactics. This malware, distributed via phishing emails, utilizes DLL side-loading to target banks in Portugal, including Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, and Santander, as well as Revolut and Wise. The campaign leverages technologies like WebRTC and STUN protocols to establish communication channels, making it difficult to detect and analyze. Recent activity has incorporated anti-analysis checks and CAPTCHA resistance, highlighting the evolving sophistication of the threat actors.
Alongside the Grandoreiro campaign, a separate threat actor is deploying the BTMOB RAT, an Android remote access trojan that emerged in February 2025. This RAT offers a range of capabilities, including device unlocking, screenshot capture, keystroke logging, and credential theft via HTML injections. Notably, BTMOB comes with an APK builder, allowing users to quickly generate customized phishing lures and adapt the malware to specific regions without requiring coding expertise. This capability significantly reduces the time and effort needed to conduct a full device compromise.
The combined use of phishing, DLL side-loading, WebRTC, and anti-analysis techniques demonstrates the increasing complexity of banking malware and the need for organizations to implement layered security defenses.
