Grandoreiro Uses DLL Sideloading in a Campaign Targeting Mexico

Summary
Acronis details a Grandoreiro campaign observed in May 2026 that sideloads a malicious DLL through Duplicate Files Finder. The malware uses extensive anti-analysis checks, and telemetry shows the most activity in Mexico.
Key points
- The campaign abuses the legitimate Duplicate Files Finder application: a malicious mingwm10.dll is loaded through a DLL sideloading chain.
- The initial ZIP archive contained decoy PDF and XML files. A spam delivery vector is suspected, but was not confirmed.
- The loader checks for sandboxes, virtual machines, analysis tools, and selected locations and system profiles before attempting C2 communication.
- The malware uses Google DNS-over-HTTPS to resolve a hardcoded C2 domain and was designed to retrieve a second-stage payload over TCP port 6432; the server was offline during analysis.
- Acronis telemetry for the last 30 days of June 2026 showed the largest concentration of detections in Mexico, with activity also observed in Spain, other Latin American countries, and North America.
- Acronis reports that Grandoreiro remains active at lower levels following the 2024 law-enforcement disruption.
Article Details
- Attack Vectors
- The analyzed ZIP archive had an invoice-like filename. Acronis assesses with moderate confidence that it was delivered through a spam campaign; the initial delivery vector was not confirmed.
- The archive contained a renamed legitimate Duplicate Files Finder executable and a malicious replacement for mingwm10.dll. The executable loads dupfdll.dll, which then loads the malicious DLL.
- After environment checks, the loader resolves a hardcoded C2 domain and requests a second-stage payload over TCP port 6432.
- Defensive Notes
- Hunt for a renamed Duplicate Files Finder executable loading mingwm10.dll from the same directory.
- Hunt for the token CLIENT_SOLICITA_DDS_MDL in egress traffic or memory.
- Investigate a GUI process that suppresses its window and then queries ip-api.com and HARDWARE\DESCRIPTION\System\BIOS in quick succession.
- Acronis reports that Acronis EDR / XDR detects and blocks this threat.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 445675885304004[.]pointto[.]us | Grandoreiro C2 domain listed as an IOC. |
| DOMAIN | b744156103040828396040[.]nhlfan[.]net | Hardcoded Grandoreiro C2 domain; the server was offline during analysis. |
| DOMAIN | beeges[.]health-carereform[.]com | Grandoreiro C2 domain listed as an IOC. |
| DOMAIN | smartpdfhub-7q2m[.]read-books[.]org | Grandoreiro C2 domain listed as an IOC. |
| DOMAIN | streamlinepdf-8m2x[.]workisboring[.]com | Grandoreiro C2 domain listed as an IOC. |
| DOMAIN | voyage[.]mydissent[.]net | Grandoreiro C2 domain listed as an IOC. |
| MD5 | 82f771c3ec4fe979c3ae00372e8c3ac8 | MD5 of the analyzed ZIP archive containing the Grandoreiro loader. |
| MD5 | f1aed8cf2adafa86927fc58d5f24073e | MD5 of the malicious replacement mingwm10.dll. |
| SHA256 | 1b2fe30c5bf57f9623efb34688580fe5bbb2c55351c5a07a6c4313bb6faa29f1 | Grandoreiro sample listed as an IOC. |
| SHA256 | 1fe5a72aefc38afeeee72d8a939f9db50800a447b7313f4d8c504771bb7fa2de | Grandoreiro sample listed as an IOC. |
| SHA256 | 2820a2e36f1cb537a7853fde2313a5158d1e3696ff81c3066ec8fe274358c22d | Grandoreiro sample listed as an IOC. |
| SHA256 | 368246eb503585f26e0151431909792b8d9be0edc229bb207be882bfb374c005 | Grandoreiro sample listed as an IOC. |
| SHA256 | 37492ecd9deb8591ea7e179ebb8e13c6b486cdacae18a6a482d9dd18f08453a3 | Grandoreiro sample listed as an IOC. |
| SHA256 | 47d5a73b220813299f753ef0a96582a8d08b853391864128a1f15271dbb42e65 | Grandoreiro sample listed as an IOC. |
| SHA256 | 609755a8c73e53f332428786c366323b3979850aaa0e075d946e6c05aa62f867 | Grandoreiro sample listed as an IOC. |
| SHA256 | 65db035f79db85ad66fb3e0365e478f95f8f648545b18360d850a7ed179c9dab | Grandoreiro sample listed as an IOC. |
| SHA256 | 684f5eb157ef2ba3ea17335d6c8c9c801f93e6eb3aa08ecbfaf5806a4b5e3b80 | Grandoreiro sample listed as an IOC. |
| SHA256 | a91c7cb932301454df4b0feed58082cae7f2d0e4078d7e6df3f53d806ed04f1d | Grandoreiro sample listed as an IOC. |
| SHA256 | ac35843c81381107d4f816681477d706c43fa75f064f2c3d99237c7282f0b798 | Grandoreiro sample listed as an IOC. |
| SHA256 | ad5762fa98da2aff24d9d6b55be5dae21d07c54679ead67252a19c2521162a87 | Grandoreiro sample listed as an IOC. |
| SHA256 | c019cfa9b50a69ff07e98bd78b3a6fc489110e5db1c0d79ada716605a2320951 | Grandoreiro sample listed as an IOC. |
| SHA256 | ca33f5608b72ecca64a002074a4103c7cb83de902ecf5c69949eecb7eef03b5a | Grandoreiro sample listed as an IOC. |
| SHA256 | cc238813ab277cbb4324d37875c37985ca5baeaf8c412b4c85aa8ec5faec7096 | Grandoreiro sample listed as an IOC. |
| SHA256 | e0491eddb45425a674e479b2590517ffef2f108add431761bb89791fc208b6e9 | Grandoreiro sample listed as an IOC. |
| SHA256 | e99416ff71e4574de4fceebdc34f3b9a6e0610f36b77b735b231bd39edb7a0a1 | Grandoreiro sample listed as an IOC. |
MITRE ATT&CK
T1016 · System Network Configuration DiscoveryThe loader contacts ip-api.com to determine the infected system's public IP address.T1057 · Process DiscoveryThe loader checks running processes against a list of 49 debugging, analysis and monitoring process names.T1071.001 · Web ProtocolsStatic analysis found that the loader makes an HTTP GET request to retrieve a second-stage payload over TCP port 6432.T1082 · System Information DiscoveryThe loader collects physical memory, processor count, free disk space, screen resolution and other host information.T1140 · Deobfuscate/Decode Files or InformationThe loader decodes runtime strings using a custom routine combining Base64 and XOR.T1497.001 · System ChecksThe loader checks uptime, desktop shortcuts, hardware characteristics, virtual-machine components, BIOS values and other environment details before contacting C2.T1564.003 · Hidden WindowThe malicious implant hides the Duplicate Files Finder application window after launch.T1574.002 · DLL Side-LoadingThe renamed Duplicate Files Finder executable loads dupfdll.dll, which loads the malicious replacement mingwm10.dll.T1614 · System Location DiscoveryThe loader obtains geolocation through ip-api.com and excludes systems in specified countries.
People
Malware
Vendors
Products
Countries
BrazilGrandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaignMexicoGrandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaignSpaina clear concentration of activity in Mexico, which accounts for the largest share of observed samples. Spain and several Latin American countries follow, forming a secondary cluster of detections. Overall, the data