Back to the radar Cybersecurity

Grandoreiro volta a atacar e usa faturas falsas

Cybersecurity

Uma nova campanha do trojan bancário Grandoreiro, identificada pela Unidade de Pesquisas de Ameaças da Acronis (Acronis Threat Research Unit – TRU), utiliza o aplicativo legítimo Duplicate Files Finder (DFF) para carregar código malicioso por meio da técnica de DLL sideloading, conforme relatório publicado pela empresa…

Uma nova campanha do trojan bancário Grandoreiro, identificada pela Unidade de Pesquisas de Ameaças da Acronis (Acronis Threat Research Unit – TRU), utiliza o aplicativo legítimo Duplicate Files Finder (DFF) para carregar código malicioso por meio da técnica de DLL sideloading, conforme relatório publicado pela empresa…

Em contexto

  • Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
  • Fonte: CISO Advisor
  • Publicado: 24/08/2026

Continuar lendo na fonte original →

Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.

Why it matters

In security the story is rarely the attack. It is the time between the intrusion and somebody noticing. That number says more about an organisation than any certificate hanging on the reception wall.

I separate technical risk from business risk, because they do not always match. A critical vulnerability in an isolated system matters less than a medium one in the system that issues invoices. Prioritising by severity without looking at where the money is is an expensive way to work hard and protect little.

What usually goes wrong

The most expensive blind spot is usually the supplier. The organisation hardens its own perimeter and grants broad access to a third party that has half those controls. A good share of the incidents I have seen in this region came in that way, and the contract said nothing about it.

What to watch

  • Whether third parties or suppliers were in the chain, because the perimeter now includes partners.
  • How long it took to detect, usually the most revealing metric in the whole case.
  • Whether initial access came from a legitimate account handled badly, which is the most frequent pattern.

How I read this entry

If this happened near an organisation I advise, the conversation I would force is not about tools. It is about the rehearsal. How many times the incident was simulated, who calls whom, what gets said to customers and when. A plan never rehearsed is not a plan, it is a document.

The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Share

Living through this in your own team?

Open the chat and tell me how you're handling it. I'm interested in comparing notes.

Keep reading

More entries from the radar

See all
Darinel Ortega Online · I reply during the day
Today
Hello. I'm not selling anything here: this is for exchanging knowledge about technology.
Write whatever you like — you can send text, images or documents. Messages reach my console and I reply from there.

An open conversation to share knowledge. Messages reach my console and I reply from there.

Let us book a conversation

Pick the day and time that work for you. Thirty minutes, no sales pitch.

Video call

For a video call, just ask for one here and I'll send you the session link.