Mexico accounted for 40% of observed detections in a renewed Grandoreiro campaign that surfaced in May 2026, Acronis’ Threat Research Unit (TRU) reported — a reminder that the Brazilian-origin banking trojan remains active and has adapted its delivery and execution techniques.
How Grandoreiro is abusing legitimate software
In the campaign described by Acronis TRU, attackers used DLL sideloading to execute Grandoreiro through a legitimate application. The malicious chain relied on the Duplicate Files Finder application: attackers renamed the trusted executable and placed a malicious mingwm10.dll alongside the program’s legitimate dependencies so that the legitimate executable would load the malicious library. The initial loader bundled encrypted strings to complicate analysis and did not contact command-and-control (C2) infrastructure until it completed an extensive environmental check.
Anti-analysis measures and environmental gating
Acronis’ analysis found that the loader performed wide-ranging anti-analysis checks before attempting C2 communication. The checks looked for virtualization and sandbox artifacts, security and analysis tools, system characteristics and specific user and machine configurations. The loader also queried the victim’s public IP address and geolocation and included a blacklist that prevented activity when traffic originated in several unspecified countries. During TRU’s dynamic review the C2 server was offline; static analysis indicated the loader would attempt to retrieve a second-stage payload only after passing its environmental gates.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadGeographic footprint: Mexico, Spain, Peru and Argentina
Telemetry captured by Acronis showed that Mexico was the largest source of detected samples in the last 30 days of June, accounting for 40% of detections. Spain followed at 17%, Peru at 13% and Argentina at 10%. Activity remained concentrated in Latin America, with smaller detection clusters in Europe and North America. These findings add to previous campaigns that targeted Mexico and to Grandoreiro’s earlier expansion into Spain, according to the TRU report.
Delivery vector assessment and operational persistence
Acronis could not confirm the initial delivery vector for this wave. An invoice-like ZIP filename found on samples, together with Grandoreiro’s historical distribution patterns, led TRU to assess with moderate confidence that spam was involved. The report also noted that overall Grandoreiro activity remained below its previous peak but continued to evolve. That persistence is notable because a major law-enforcement operation in January 2024 had disrupted parts of the malware’s infrastructure, yet the operation has not been eliminated.
What this means for technologists, policymakers, and end users
- Technologists and security teams: prioritize detection and response for DLL sideloading involving legitimate binaries, including unexpected copies of Duplicate Files Finder and the presence of mingwm10.dll alongside trusted executables; monitor for encrypted strings and behavioral indicators tied to environmental checks and second-stage retrieval attempts.
- Policymakers and law enforcement: the January 2024 disruption reduced but did not eliminate Grandoreiro’s activity; continued operational pressure and international coordination will be necessary to address an operation that adapts its delivery and execution methods and remains regionally concentrated.
- End users and enterprise procurement leaders: be alert to invoice-like ZIP attachments as a plausible delivery vector and consider controls that flag renamed executables and unexpected DLLs placed in application directories, particularly for software that can be side-loaded by design.
Grandoreiro’s reappearance shows a familiar pattern: a financially motivated malware family that evolves tactics to survive disruption. By sideloading through a legitimate tool, gating execution behind environmental checks and hiding strings with encryption, the campaign raises the bar for detection while keeping its target set focused on Latin America — most prominently Mexico. The question left by Acronis’ findings is not whether the trojan can return, but how defenders and law enforcement will respond to an operation that has repeatedly adapted since the 2024 disruption.
Read the original Acronis TRU report: https://www.infosecurity-magazine.com/news/grandoreiro-mexico-dll-sideloading/




