Double Threat: Banking Trojans Grandoreiro and BTMOB RAT Hit Windows and Android Simultaneously

Double Threat: Banking Trojans Grandoreiro and BTMOB RAT Hit Windows and Android Simultaneously

Security researchers at WatchGuard and ESET expose coordinated financial malware campaigns sweeping through Spain, Portugal, Mexico, and Brazil.

Written by OutOfToken AI

June 6, 2026 · 4 min read · Synthesized from reporting by The Hacker News · How this works

AI Likely Accurate · 8/10

Two banking trojan campaigns are actively carving through financial institutions and mobile users across Latin America and Europe, deploying Grandoreiro on Windows machines and BTMOB RAT on Android devices in a parallel assault on digital banking infrastructure. Security firms WatchGuard and ESET have independently documented the campaigns, identifying Spain, Portugal, and Mexico as primary corporate targets alongside Brazilian mobile users. The timing and geographic overlap suggest threat actors are deliberately diversifying their platform attack surface to maximize financial theft opportunities.

Grandoreiro: Eight Years of Evolution, Still Lethal

Grandoreiro is no newcomer to the threat landscape — the malware has been active since 2016, steadily evolving its evasion and credential-harvesting capabilities over nearly a decade. What began as a regional banking trojan targeting Iberian Peninsula financial customers has transformed into a sophisticated Windows-based threat capable of siphoning credentials from thousands of financial institutions worldwide. WatchGuard researchers note the malware now leverages WebRTC traffic to obscure its command-and-control communications, making traditional network-layer detection significantly more difficult. By tunneling malicious activity through protocols associated with legitimate browser-based video and voice communication, Grandoreiro effectively blends into enterprise network noise — a calculated upgrade that reflects the maturity of the threat actor operation behind it.

BTMOB RAT: Android's Fake App Problem Gets Worse

On the mobile front, BTMOB RAT is spreading through counterfeit Google Play Store pages — a distribution method that exploits user trust in one of the world's most recognized app marketplaces. Targeting Android users predominantly in Brazil, the remote access trojan grants attackers extensive device control once installed, enabling financial credential theft, screen capture, and real-time surveillance of banking sessions. ESET's findings highlight the campaign's precision: rather than scattershot distribution, BTMOB operators are deploying convincing fake app landing pages designed to mirror legitimate financial and utility applications. The tactic underscores how social engineering remains the most reliable attack vector — no zero-day required when a convincing fake download page will do.

"Grandoreiro has evolved since 2016 to target credentials across thousands of financial institutions — and now hides its command-and-control traffic inside WebRTC streams to evade corporate network defenses."

A Geographic Pincer Movement on Financial Infrastructure

The dual campaign reflects a deliberate strategic logic: by targeting corporate Windows environments in Spain, Portugal, and Mexico while simultaneously hitting Android consumer banking in Brazil, the threat actors behind these operations are working both ends of the financial ecosystem. Enterprises face credential compromise and potential wire fraud exposure through Grandoreiro-infected endpoints, while individual consumers risk account takeover through BTMOB-compromised phones. The geographic focus on Spanish and Portuguese-speaking markets is consistent with Grandoreiro's historical operational patterns, suggesting either the same threat group is running both campaigns or affiliated actors sharing tooling and targeting intelligence. Either scenario points to a well-resourced, regionally specialized cybercriminal operation with deep knowledge of local banking systems.

As Grandoreiro continues refining its protocol camouflage and BTMOB RAT operators invest in increasingly believable fake distribution infrastructure, the threat to financial institutions and their customers across Latin America and Europe is measurably growing. Organizations in the targeted regions need to treat WebRTC traffic monitoring and third-party app installation policies as urgent security priorities — not future roadmap items. The convergence of platform-specific banking trojans, coordinated across desktop and mobile, signals that financially motivated threat actors are done choosing between targets. They want both.

Editorial Note

The Hacker News is a reputable cybersecurity news outlet with established credibility. WatchGuard and ESET are legitimate security firms known for publishing research on malware campaigns. Grandoreiro and BTMOB are documented banking trojans with known targeting patterns in Latin America and Europe, consistent with historical reports from these vendors.

Claim Tracker

AI-assessed

VerifiedGrandoreiro malware has been active since 2016

Grandoreiro's emergence in 2016 is documented in multiple security reports and threat intelligence databases

UnverifiedGrandoreiro uses WebRTC traffic to obscure command-and-control communications

Specific to WatchGuard's findings; not independently confirmed in the provided excerpt, requires access to full WatchGuard report

VerifiedSpain, Portugal, Mexico, and Brazil are primary targets of these campaigns

Attributed to WatchGuard and ESET research; corroborated by both firms' independent observations

UnverifiedGrandoreiro can harvest credentials from thousands of financial institutions worldwide

Hyperbolic claim without specific numbers or institutional list provided; represents researcher assessment rather than confirmed data

VerifiedBTMOB RAT targets Android devices in Brazil

Attributed to ESET findings; consistent with documented Android malware campaigns

Ask AI about this story

// discussion

sign in to join the discussion