{"id":237860,"date":"2026-05-28T03:42:36","date_gmt":"2026-05-28T08:42:36","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/05\/grandoreiro-malware-and-btmob-rat-campaigns-target-windows-and-android-users"},"modified":"2026-05-28T03:42:36","modified_gmt":"2026-05-28T08:42:36","slug":"grandoreiro-malware-and-btmob-rat-campaigns-target-windows-and-android-users","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/05\/grandoreiro-malware-and-btmob-rat-campaigns-target-windows-and-android-users","title":{"rendered":"Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users"},"content":{"rendered":"<p><\/p>\n<p><iframe style=\"display: block; margin: 0 auto; width: 100%; aspect-ratio: 4\/3; object-fit: contain;\" src=\"https:\/\/www.youtube.com\/embed\/fC9jSOS7tSE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; encrypted-media; gyroscope;\n   picture-in-picture\" allowfullscreen><\/iframe><\/p>\n<p>Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively.<\/p>\n<p>That\u2019s according to new findings from WatchGuard and ESET, which have observed the two malware families being used to single out companies in Spain, Portugal, and Mexico, as well as mobile users in Brazil.<\/p>\n<p>The <a href=\"https:\/\/thehackernews.com\/2024\/10\/new-grandoreiro-banking-malware.html\">Grandoreiro<\/a> campaign \u201cuses the DLL Side-Loading technique abusing four different software, targeting banks in Portugal,\u201d WatchGuard researcher Euler Neto <a href=\"https:\/\/www.watchguard.com\/wgrd-security-hub\/secplicity-blog\/grandoreiro-malware-campaign-targets-europe-and-latin-america\">said<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That\u2019s according to new findings from WatchGuard and ESET, which have observed the two malware families being used to single out companies in Spain, Portugal, and Mexico, as [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,45,6],"tags":[],"class_list":["post-237860","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-finance","category-robotics-ai"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/237860","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=237860"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/237860\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=237860"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=237860"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=237860"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}