The Grandoreiro and BTMOB campaigns show how financial malware is expanding across both desktop and mobile environments. Grandoreiro continues to target Windows users, while BTMOB is focused on Android devices, with both campaigns aimed at banking fraud, credential theft, and remote control of victim systems.
This is especially concerning because users now access banking, payments, email, business apps, and authentication tools across multiple devices. A compromised Windows machine can expose browser sessions, banking activity, and business credentials, while a compromised Android phone can give attackers access to SMS messages, notifications, banking apps, contacts, and MFA prompts. Because naturally the device used to approve access has also become the device attackers want to control.
The report notes that Grandoreiro is being used in campaigns targeting Latin America and Europe, while BTMOB is being distributed through phishing pages and fake Android applications. BTMOB also appears to lower the barrier for attackers by providing ready-made campaign tooling, making mobile banking fraud easier to scale.
Users should avoid downloading apps from unofficial sources, verify banking-related messages before clicking links, and be cautious of attachments or prompts that ask them to install software. Organizations should strengthen endpoint protection, mobile threat defense, phishing detection, DNS filtering, and transaction monitoring. Banks and financial institutions should also watch for suspicious device fingerprints, unusual login behavior, session hijacking, and remote-control indicators.
The bigger lesson is simple: financial malware is no longer limited to one device type. Attackers follow the money, the credentials, and the authentication flow. If banking and identity now move between Windows desktops and Android phones, then protection must also cover both. Treating mobile security as optional is exactly the kind of optimism fraud operators quietly appreciate.

Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That's according to new findings from WatchGuard and ESET, which have observed the two malware families being used to single out companies in Spain, Portugal, and Mexico, as well as mobile users in Brazil. The
Source: Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users via The Hacker News — published 27 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.