216.73.216.6

Grandoreiro Trojan Distributed via Contabo-Hosted Servers in Phishing Campaigns

· Published 08/04/2025 10:32 · Modified 08/04/2025 11:55

Export JSON

Essential information

Published
08/04/2025 10:32
Modified
08/04/2025 11:55
Tags
2025-04-08 contabo grandoreiro mediafire
Related entities
9 techniques (mitre), 1 malware, 4 others

Description

Cybercriminals are reviving the banking trojan, targeting users in Latin America and Europe through large-scale phishing campaigns. The malware is distributed via emails impersonating tax agencies, leading victims to download malicious payloads from -hosted servers and . The attack chain involves obfuscated VBS scripts and a Delphi-based EXE that steals credentials and connects to a C2 server. The campaign employs dynamic URLs, social engineering, and various obfuscation techniques to evade detection. Users in Mexico, Argentina, and Spain are primary targets, with the malware searching for Bitcoin wallet directories and system information. Frequent changes to subdomains under contaboserver[.]net are used to avoid detection.

External references