Malware variant targeting banks discovered

NGUYỄN ĐĂNG |

Variants of the Grandoreiro malware are becoming one of the major threats worldwide.

At the Security Analyst Summit (SAS) 2024, Kaspersky's Global Research and Analysis Team (GReAT) revealed a remarkable discovery: A Lite version of the Grandoreiro malware is targeting around 30 banks in Mexico.

Grandoreiro is currently one of the top threats in the banking security space, having targeted more than 1,700 banks and accounting for 5% of all banking trojan attacks globally this year.

Mexico is one of the hardest hit countries, with over 51,000 attacks involving Grandoreiro variants, including the aforementioned Lite version.

According to cybersecurity experts, cybercriminals have split Grandoreiro's source code into lightweight trojan versions (malware disguised as useful software or applications) to deploy new attack campaigns.

“When you look at all the malware that has been developed recently, it is not difficult to see that the threat landscape is becoming increasingly complex. The lightweight versions could signal a trend of attacks spreading outside of Latin America,” explains Fabio Assolini, head of Kaspersky’s Global Research and Analysis Team (GReAT) for Latin America.

Different variants of Grandoreiro, including the original malware and the lite version, accounted for about 5% of global banking attacks using the trojan detected by Kaspersky in 2024. This shows that Grandoreiro variants have become one of the most powerful threats worldwide.

Since 2024, Kaspersky has also analyzed new variants of the Grandoreiro malware and discovered that criminals are applying many new attack tactics.

For example, malware will record computer mouse activity to simulate real user behavior patterns, in order to bypass security systems based on machine learning to analyze behavior.

By simulating natural movements similar to a real user swiping a computer mouse, malware can “trick” anti-phishing tools and detect unusual behavior in the system.

Additionally, Grandoreiro uses an encryption technique that cybersecurity experts have never encountered in previous malware, making it difficult to detect and analyze cyber attacks.

According to data from Kaspersky, the Grandoreiro malware has been active since 2016.

By 2024, the threat had targeted more than 1,700 financial institutions and 276 cryptocurrency wallets across 45 countries and territories.

Most recently, Asia and Africa have been added to Grandoreiro's target list; Grandoreiro has truly become a global financial threat.

NGUYỄN ĐĂNG
RELATED NEWS

Forecast of severe cold developments in the 2 peak months of winter

|

Forecast for January and February - the main winter months, cold air will continue to be weaker than average but widespread cold spells may still appear.

Secretary of Bac Ninh Provincial Party Committee Nguyen Hong Thai: Building Bac Ninh into a centrally-run city before 2030

|

In the atmosphere of the 14th National Party Congress, Comrade Nguyen Hong Thai, Member of the Party Central Committee, Secretary of the Bac Ninh Provincial Party Committee, interviewed central and local press agencies about the vision, goals and major orientations to build Bac Ninh to develop rapidly, sustainably, modernly, and with rich identity; striving to become a centrally-run city before 2030.

Fall of canal banks in Ho Chi Minh City

|

Ho Chi Minh City - Ho Chi Minh City functional forces are blocking Ba Dinh street, Chanh Hung ward after a 50m long canal bank subsidence incident.

Truck fire on Cam Lam - Vinh Hao expressway, traffic congestion of more than 1km

|

Khanh Hoa - A truck fire while traveling on the Cam Lam - Vinh Hao expressway caused traffic congestion through the area lasting more than 1km.

Hanoi plans to spend more than 87,000 billion VND to build 25 more specialized parks

|

Hanoi - The city plans to build 25 specialized parks covering over 2,000ha with a total investment of over 87,645 billion VND.

Stocks are in an attractive valuation zone

|

The new growth cycle of the stock market will be based on the foundation of corporate profits and upgrade expectations.

Iranian leader accuses Trump of inciting protests

|

Mr. Trump was blamed by Iranian leader, saying that the US leader's statement fueled instability and casualties in the protests.

Cultivating the belief and aspiration to develop a prosperous, civilized, and happy country

|

In the preparation for the 14th National Congress of the Party, information and propaganda play a particularly important role in orienting public opinion, consolidating trust and spreading vision and aspirations for development. Talking to reporters of Nhan Dan Newspaper, Comrade Lai Xuan Mon, Member of the Party Central Committee, Standing Deputy Head of the Central Propaganda and Mass Mobilization Committee, Director of the Press Center of the 14th Congress, clarified the outstanding results, key orientations and requirements set for the press in the peak propaganda campaign towards the 14th Congress.

Phát tán mã độc chiếm đoạt dữ liệu, hưởng lợi chục tỉ đồng

Việt Dũng |

Nguyễn Văn Anh cùng đồng phạm phát triển mã độc, dùng thủ đoạn vờ tuyển dụng nhân sự dụ cho nạn nhân sập bẫy, rồi chiếm đoạt dữ liệu của họ.

Lừa đảo đặt phòng, chủ homestay mất tiền cọc vì link mã độc

nhóm pv |

Lợi dụng tình trạng khan hiếm phòng nghỉ dịp lễ 2.9, các đối tượng lừa đảo đã mạo danh khách sạn, homestay trên mạng xã hội để lừa tiền đặt cọc.

Gia tăng ồ ạt các đợt tấn công bằng mã độc tống tiền

Cẩm Hà - Khánh An |

Chỉ trong ít tháng đầu năm, thống kê của Cục An toàn thông tin (Bộ Thông tin và Truyền thông) cho thấy có hơn 300.000 nguy cơ tấn công mạng nhằm vào các hệ thống thông tin trên toàn quốc. Hệ thống của Trung tâm Giám sát không gian mạng quốc gia - NCSC cũng ghi nhận hơn 13.000 sự kiện an toàn thông tin liên quan đến mã độc ransomware trên các hệ thống thông tin.