The images in this article were generated with artificial intelligence. How we publish
Two recent campaigns, one directed at Windows teams using the Grandoreiro banking trojan and one directed at Android mobile with the RAT BTMOB, confirm a trend that response teams have already been warning: financial crime combines sophisticated technical tools with legitimate services to make it difficult to detect and fast to scale.
In the case attributed to Grandoreiro, the attackers have renewed classic tactics - phishing by email and compressed files - and have mixed them with techniques of avoidance and abuse of legitimate software. The use of DLL side-loading allows operators to launch malicious bookstores by posing as components of reliable applications; in addition, the analyzed samples incorporate modules written in Delphi and libraries that establish P2P communications using STUN and ICE, which camouflages them within video conference traffic and makes it difficult to identify them by simple signatures.

The files detected are directed against financial institutions in Portugal and payment platforms and neobanks, but distribution patterns and anti-analysis and CAPTCHA checks point to a campaign designed to persist and adapt after previous police actions. This hybrid approach - phishing, side-loading, cloud service abuse and anti-analysis controls - is exactly what increases the operating cost for defenders and reduces the effectiveness of surface controls.
In the mobile ecosystem, BTMOB represents another side of the same problem: a Trojan that exists in the "RAT-as-a-Service" mode and that facilitates the conversion of smartphones into complete vectors of fraud and espionage. Its typical mechanism combines supplanting sites, misleading APK files and abuse of Android accessibility service to scale privileges without additional user interaction. The risk increases because the product is marketed with an APKS builder and panels ready to operate, allowing attackers with little technical knowledge to set up regionalized campaigns quickly.
The marketing and leakage of the source code cause powerful tools to pass to less sophisticated actors, multiplying the threat surface. When a malicious product is sold by subscription or with perpetual licenses and filtered, rules change: imitators proliferate, entry barriers are reduced and illegal economies grow around initial access and the resale of credentials.
The implications for companies and users are clear: detection based exclusively on signatures or block lists is insufficient. Financial organizations, service providers and IT departments should combine preventive controls, behavioral detection and active response. For Windows this involves policies of restricted execution (application whiteling), strict DLL load control, application integrity protection, process analysis using unsigned libraries and more aggressive mail controls that block direct downloads from external links.
In mobility, the immediate recommendation is to stop the installation outside of official stores and to review permits: not to provide accessibility services to unverified applications, keep mobile malware protection up to date, activate Google Play Protect, and apply MDM policies that limit APKS installation and control sensitive permissions settings. Education remains vital: awareness campaigns focused on mobile phishing and URLs verification reduce infection rates.
In addition, any money-managing entity should strengthen authentication and fraud signals: implement session-resistant MFA, detect abnormal behavior in transactions, transfer limits by new devices and off-band confirmation procedures for critical operations. At the network level, monitoring unusual WebRTC / STUN / ICE patterns and outgoing traffic to unexpected infrastructure can give early signs of exfiltration or malicious P2P tunnels.

For individual users the most effective is basic prevention: distrust of unexpected emails and messages that ask to download files or update applications, avoid installing APKS from third-party repositories, keep system and applications up to date, and use unique passwords with multifactor authentication in financial services. If an infection is suspected, isolate the equipment or device, change credentials from another safe device and consult with the bank about possible blockages are critical steps.
The intelligence pieces in this case come from firms and research firms that document the campaigns; security teams and risk managers must incorporate these indicators into their rules and actively share IOC and TTP in their local and sectoral communities. The WatchGuard page and the analyses published by ESET, which have disseminated details about both families and their evolution, are available for the following technical research and newsletters: WatchGuard Threat Lab and ESET WeLiveSecurity.
In short, these operations show that financial attackers prefer to combine social engineering, reuse legitimate infrastructure and "ready-to-use" kits to scale quickly. The response must be equally multifaceted: technical hardening, behaviour-based detection, permit governance and constant user training.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...