Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
WatchGuard and ESET say Grandoreiro and BTMOB are spreading through phishing, DLL side-loading, and fake app sites to hit banks and mobile users in Europe and Latin America.
Intelligence analysis by GPT-5.4 Mini
The article says two financially motivated malware campaigns are active at once: Grandoreiro on Windows and BTMOB on Android. Both rely on social engineering and disguise their traffic or installers to evade detection and steal banking access.
Two bad computer programs are being used to steal money and secrets. One attacks Windows computers, and the other attacks Android phones. Both trick people first, like a scammer wearing a fake badge.
The computer one hides inside normal-looking files and talks in ways that are hard to notice, a bit like a burglar using a crowded subway to slip away unseen. The phone one hides behind fake app pages and asks for extra powers after it is installed.
The important part is that these scams keep changing. That means security teams cannot only look for one old trick; they need to watch for fake emails, fake download pages, and strange file behavior too.
Analysis
Grandoreiro campaign
WatchGuard says Grandoreiro is still evolving and is being used against companies and financial users in Spain, Portugal, Mexico, and other parts of Latin America and Europe. The malware has been active since 2016 and is described as capable of stealing credentials linked to thousands of financial institutions across 45 countries and territories.
The latest campaign uses phishing emails and DLL side-loading, including DLLs developed in Delphi 11. WatchGuard says some of the components use the sgcWebSockets library for peer-to-peer and WebRTC-related communications, with STUN and ICE protocols helping the malware reach across NAT boundaries. The point, the report argues, is to make the traffic look like ordinary web-conferencing activity, which is noisy and harder to monitor.
The campaign also includes DLLs that reference Portuguese banks and financial services such as Abanca, Banco de Portugal, BBVA PT, Caixa Geral Depositos, Santander, Revolut, and Wise. Another Grandoreiro delivery chain uses a Mediafire-hosted ZIP file containing obfuscated Visual Basic Script, which launches an executable posing as an Adobe Reader update. That path leads into checks meant to hinder analysis before the final payload is run.
BTMOB on Android
ESET says BTMOB is an Android RAT that first appeared in February 2025 and can unlock devices, capture screenshots, log keystrokes, automate credential theft through HTML injections, and enable remote control. A later version added Alipay PIN capture.
The malware is sold with an APK builder, letting customers generate payloads without coding and tailor lures quickly. Its main spread method is social engineering: fake sites pretend to be streaming or crypto-mining services, then redirect victims to bogus Google Play listings that deliver the APK. Once installed, it asks for accessibility permissions and uses them to gain more control.
ESET says BTMOB is likely the successor to CraxsRAT, CypherRAT, and SpySolr. The latest version noted in the article is 4.5.5, and the malware is advertised at $700 per month, with a lifetime license priced at $1,200 and source code at $7,000.
Key points
- Grandoreiro is being used in phishing campaigns against banks and financial users in Europe and Latin America.
- WatchGuard says the malware uses DLL side-loading and web-traffic-like communication to make detection harder.
- A separate Grandoreiro chain uses a Mediafire ZIP, obfuscated VBS, and a fake Adobe Reader update lure.
- ESET says BTMOB is an Android RAT sold with an APK builder and spread through fake sites and app listings.
- BTMOB can steal credentials, capture screenshots, log keystrokes, and abuse accessibility permissions.



