ATT&CKReferencesIBM Grandoreiro April 2020

IBM Grandoreiro April 2020

Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareGrandoreiro

Grandoreiro has named malicious browser extensions and update files to appear legitimate.

T1071.001
Web Protocols
MalwareGrandoreiro

Grandoreiro has the ability to use HTTP in C2 communications.

T1102.002
Bidirectional Communication
MalwareGrandoreiro

Grandoreiro can utilize web services including Google sites to send and receive C2 data.

T1105
Ingress Tool Transfer
MalwareGrandoreiro

Grandoreiro can download its second stage from a hardcoded URL within the loader's code.

T1115
Clipboard Data
MalwareGrandoreiro

Grandoreiro can capture clipboard data from a compromised host.

T1176.001
Browser Extensions
MalwareGrandoreiro

Grandoreiro can use malicious browser extensions to steal cookies and other user information.

T1185
Browser Session Hijacking
MalwareGrandoreiro

Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1189
Drive-by Compromise
MalwareGrandoreiro

Grandoreiro has used compromised websites and Google Ads to bait victims into downloading its installer.

T1204.001
Malicious Link
MalwareGrandoreiro

Grandoreiro has used malicious links to gain execution on victim machines.

T1204.002
Malicious File
MalwareGrandoreiro

Grandoreiro has infected victims via malicious attachments.

T1539
Steal Web Session Cookie
MalwareGrandoreiro

Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device.

T1547.001
Registry Run Keys / Startup Folder
MalwareGrandoreiro

Grandoreiro can use run keys and create link files in the startup folder for persistence.

T1547.009
Shortcut Modification
MalwareGrandoreiro

Grandoreiro can write or modify browser shortcuts to enable launching of malicious browser extensions.

T1555.003
Credentials from Web Browsers
MalwareGrandoreiro

Grandoreiro can steal cookie data and credentials from Google Chrome.

T1566.002
Spearphishing Link
MalwareGrandoreiro

Grandoreiro has been spread via malicious links embedded in e-mails.

T1573.002
Asymmetric Cryptography
MalwareGrandoreiro

Grandoreiro can use SSL in C2 communication.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.