{"id":3522,"date":"2021-08-13T22:16:17","date_gmt":"2021-08-14T03:16:17","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3522"},"modified":"2021-08-13T22:16:18","modified_gmt":"2021-08-14T03:16:18","slug":"tetrade-family-of-banking-trojans","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/","title":{"rendered":"Tetrade family of banking Trojans"},"content":{"rendered":"\n<p>Brazil is famous for the numerous banking Trojans developed by local criminals. In the criminal underworld of this country are some of the most active and creative cybercriminals in the world. Like their counterparts in China and Russia, their cyberattacks have a strong local flavor, and were long limited to local bank customers. But now its attacks and operations are aggressively expanding beyond its borders, attacking banks in other countries. Tetrade is our description of four great families of banking Trojans, created, developed and propagated by Brazilian pirates, but now on a global scale.<\/p>\n\n\n\n<p>The Trojans that we are going to see today are the main software distributed by Tetrade. Let&#8217;s start with Grandoreiro, which is a family of banking Trojans that began operating in Brazil and later in Western Europe. Our always trustworthy Kaspersky has witnessed Grandoreiro&#8217;s campaigns since at least 2016 and in fact attackers have been regularly improving their techniques, striving to remain undetectable and active for longer. Based on the analysis of the campaigns carried out by the company, it could be stated that Grandoreiro operates as a malware-as-a-service (MaaS) project. Since January 2020, Kaspersky&#8217;s telemetry shows that Grandoreiro has mainly attacked Brazil, Mexico, Spain, Portugal and Turkey but this may be temporary, we do not know if they will expand further.<\/p>\n\n\n\n<p>As for Melcoz, it is the other main most active software and this family of banking Trojans developed by the Tetrade group has been active since at least 2018. Usually, the malware uses AutoIt or VBS scripts, added in MSI files, which they execute malicious DLLs using the DLL-Hijack technique, in order to bypass security solutions. This malware steals passwords from browsers and device memory, providing remote access to capture Internet banking access. It also includes a module for theft of Bitcoin wallets and although these have not been distributed to many parts of the world, we cannot rule out that they will expand in the future as we saw before.<\/p>\n\n\n\n<p>More topics:<br><a href=\"https:\/\/truxgoservers.com\/blog\/icedid-dangerous-banking-trojan\/\">IcedID dangerous banking trojan<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/trickbot-malware-that-steals-banking-credentials\/\">Trickbot malware that steals banking credentials<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/bizarro-dangerous-new-banking-trojan\/\">Bizarro dangerous new banking Trojan<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Brazil is famous for the numerous banking Trojans developed by local criminals. In the criminal underworld of this country are some of the most active and creative cybercriminals in the world. Like their counterparts in China and Russia, their cyberattacks have a strong local flavor, and were long limited to local bank customers. But now [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3523,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,176],"class_list":["post-3522","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-trojans"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Tetrade family of banking Trojans - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today we will see a family of Trojans of Brazilian origin that has been active and at a time which is known as Tetrade.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Tetrade family of banking Trojans - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today we will see a family of Trojans of Brazilian origin that has been active and at a time which is known as Tetrade.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-14T03:16:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-14T03:16:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Tetrade.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"710\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Tetrade family of banking Trojans\",\"datePublished\":\"2021-08-14T03:16:17+00:00\",\"dateModified\":\"2021-08-14T03:16:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/\"},\"wordCount\":349,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Tetrade.jpg\",\"keywords\":[\"Cybersecurity\",\"Trojans\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/\",\"name\":\"Tetrade family of banking Trojans - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Tetrade.jpg\",\"datePublished\":\"2021-08-14T03:16:17+00:00\",\"dateModified\":\"2021-08-14T03:16:18+00:00\",\"description\":\"Today we will see a family of Trojans of Brazilian origin that has been active and at a time which is known as Tetrade.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Tetrade.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/Tetrade.jpg\",\"width\":710,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/tetrade-family-of-banking-trojans\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Tetrade family of banking Trojans\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Tetrade family of banking Trojans - Truxgo Server Blog","description":"Today we will see a family of Trojans of Brazilian origin that has been active and at a time which is known as Tetrade.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/","og_locale":"es_MX","og_type":"article","og_title":"Tetrade family of banking Trojans - Truxgo Server Blog","og_description":"Today we will see a family of Trojans of Brazilian origin that has been active and at a time which is known as Tetrade.....","og_url":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-08-14T03:16:17+00:00","article_modified_time":"2021-08-14T03:16:18+00:00","og_image":[{"width":710,"height":400,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Tetrade.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Tetrade family of banking Trojans","datePublished":"2021-08-14T03:16:17+00:00","dateModified":"2021-08-14T03:16:18+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/"},"wordCount":349,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Tetrade.jpg","keywords":["Cybersecurity","Trojans"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/","url":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/","name":"Tetrade family of banking Trojans - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Tetrade.jpg","datePublished":"2021-08-14T03:16:17+00:00","dateModified":"2021-08-14T03:16:18+00:00","description":"Today we will see a family of Trojans of Brazilian origin that has been active and at a time which is known as Tetrade.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Tetrade.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/Tetrade.jpg","width":710,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/tetrade-family-of-banking-trojans\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Tetrade family of banking Trojans"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3522"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3522\/revisions"}],"predecessor-version":[{"id":3555,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3522\/revisions\/3555"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3523"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3522"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3522"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}