Banking Trojan 'Grandoreiro' Returns With New Tricks Despite Police Takedown
A well-known banking Trojan called Grandoreiro has reappeared in a fresh campaign targeting users in Mexico, despite an earlier law enforcement operation aimed at dismantling it. Researchers report that the malware has been updated with new features specifically designed to make it harder for security tools and analysts to detect and study.
Grandoreiro is designed to steal banking credentials and financial information from infected devices, and its return shows that takedowns don't always mean the end of a threat—operators often rebuild and improve their tools to stay ahead of defenders. This pattern is common in cybercrime: malware families thought to be neutralised can resurface with upgraded evasion capabilities, making ongoing vigilance essential.
While this particular campaign is currently focused on Mexico, banking Trojans like Grandoreiro often expand to new regions over time, and Australian businesses with international customers, staff, or banking relationships should stay alert to similar threats. Keeping software updated and using layered security defences remains one of the best ways to reduce exposure to evolving malware.