Grandoreiro Uses DLL Sideloading in a Campaign Targeting Mexico

· Original article ↗

Summary

Acronis details a Grandoreiro campaign observed in May 2026 that sideloads a malicious DLL through Duplicate Files Finder. The malware uses extensive anti-analysis checks, and telemetry shows the most activity in Mexico.

Key points

  • The campaign abuses the legitimate Duplicate Files Finder application: a malicious mingwm10.dll is loaded through a DLL sideloading chain.
  • The initial ZIP archive contained decoy PDF and XML files. A spam delivery vector is suspected, but was not confirmed.
  • The loader checks for sandboxes, virtual machines, analysis tools, and selected locations and system profiles before attempting C2 communication.
  • The malware uses Google DNS-over-HTTPS to resolve a hardcoded C2 domain and was designed to retrieve a second-stage payload over TCP port 6432; the server was offline during analysis.
  • Acronis telemetry for the last 30 days of June 2026 showed the largest concentration of detections in Mexico, with activity also observed in Spain, other Latin American countries, and North America.
  • Acronis reports that Grandoreiro remains active at lower levels following the 2024 law-enforcement disruption.

Article Details

Attack Vectors
  • The analyzed ZIP archive had an invoice-like filename. Acronis assesses with moderate confidence that it was delivered through a spam campaign; the initial delivery vector was not confirmed.
  • The archive contained a renamed legitimate Duplicate Files Finder executable and a malicious replacement for mingwm10.dll. The executable loads dupfdll.dll, which then loads the malicious DLL.
  • After environment checks, the loader resolves a hardcoded C2 domain and requests a second-stage payload over TCP port 6432.
Defensive Notes
  • Hunt for a renamed Duplicate Files Finder executable loading mingwm10.dll from the same directory.
  • Hunt for the token CLIENT_SOLICITA_DDS_MDL in egress traffic or memory.
  • Investigate a GUI process that suppresses its window and then queries ip-api.com and HARDWARE\DESCRIPTION\System\BIOS in quick succession.
  • Acronis reports that Acronis EDR / XDR detects and blocks this threat.

Indicators of compromise

TypeIndicatorContext
DOMAIN445675885304004[.]pointto[.]usGrandoreiro C2 domain listed as an IOC.
DOMAINb744156103040828396040[.]nhlfan[.]netHardcoded Grandoreiro C2 domain; the server was offline during analysis.
DOMAINbeeges[.]health-carereform[.]comGrandoreiro C2 domain listed as an IOC.
DOMAINsmartpdfhub-7q2m[.]read-books[.]orgGrandoreiro C2 domain listed as an IOC.
DOMAINstreamlinepdf-8m2x[.]workisboring[.]comGrandoreiro C2 domain listed as an IOC.
DOMAINvoyage[.]mydissent[.]netGrandoreiro C2 domain listed as an IOC.
MD582f771c3ec4fe979c3ae00372e8c3ac8MD5 of the analyzed ZIP archive containing the Grandoreiro loader.
MD5f1aed8cf2adafa86927fc58d5f24073eMD5 of the malicious replacement mingwm10.dll.
SHA2561b2fe30c5bf57f9623efb34688580fe5bbb2c55351c5a07a6c4313bb6faa29f1Grandoreiro sample listed as an IOC.
SHA2561fe5a72aefc38afeeee72d8a939f9db50800a447b7313f4d8c504771bb7fa2deGrandoreiro sample listed as an IOC.
SHA2562820a2e36f1cb537a7853fde2313a5158d1e3696ff81c3066ec8fe274358c22dGrandoreiro sample listed as an IOC.
SHA256368246eb503585f26e0151431909792b8d9be0edc229bb207be882bfb374c005Grandoreiro sample listed as an IOC.
SHA25637492ecd9deb8591ea7e179ebb8e13c6b486cdacae18a6a482d9dd18f08453a3Grandoreiro sample listed as an IOC.
SHA25647d5a73b220813299f753ef0a96582a8d08b853391864128a1f15271dbb42e65Grandoreiro sample listed as an IOC.
SHA256609755a8c73e53f332428786c366323b3979850aaa0e075d946e6c05aa62f867Grandoreiro sample listed as an IOC.
SHA25665db035f79db85ad66fb3e0365e478f95f8f648545b18360d850a7ed179c9dabGrandoreiro sample listed as an IOC.
SHA256684f5eb157ef2ba3ea17335d6c8c9c801f93e6eb3aa08ecbfaf5806a4b5e3b80Grandoreiro sample listed as an IOC.
SHA256a91c7cb932301454df4b0feed58082cae7f2d0e4078d7e6df3f53d806ed04f1dGrandoreiro sample listed as an IOC.
SHA256ac35843c81381107d4f816681477d706c43fa75f064f2c3d99237c7282f0b798Grandoreiro sample listed as an IOC.
SHA256ad5762fa98da2aff24d9d6b55be5dae21d07c54679ead67252a19c2521162a87Grandoreiro sample listed as an IOC.
SHA256c019cfa9b50a69ff07e98bd78b3a6fc489110e5db1c0d79ada716605a2320951Grandoreiro sample listed as an IOC.
SHA256ca33f5608b72ecca64a002074a4103c7cb83de902ecf5c69949eecb7eef03b5aGrandoreiro sample listed as an IOC.
SHA256cc238813ab277cbb4324d37875c37985ca5baeaf8c412b4c85aa8ec5faec7096Grandoreiro sample listed as an IOC.
SHA256e0491eddb45425a674e479b2590517ffef2f108add431761bb89791fc208b6e9Grandoreiro sample listed as an IOC.
SHA256e99416ff71e4574de4fceebdc34f3b9a6e0610f36b77b735b231bd39edb7a0a1Grandoreiro sample listed as an IOC.

MITRE ATT&CK

People

Malware

Vendors

Products

Countries

Industries

Related Articles