Mark RadarMARK RADAR
EN
Event File FINTECH Financial Cybersecurity

Windows Banking Trojan Grandoreiro Adds WebRTC, DLL Sideloading to Evade Detection

1 reports · First detected 2026-06-02 · Last active 2026-06-02

Grandoreiro is a banking Trojan targeting Windows devices, primarily threatening financial institutions and bank customers in Europe and Latin America. Attackers can use it to steal online banking credentials, including usernames and passwords, and even intercept transactions. Its evolving capabilities therefore pose a direct risk to personal assets and financial-system security.

Cybersecurity firm WatchGuard recently disclosed that a new Grandoreiro variant uses DLL sideloading to load malicious components through legitimate programs. It also uses WebRTC to establish covert connections and reduce the likelihood of detection by security tools. The report did not disclose the exact discovery date, the value of losses or the number of infections.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)