Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

2026-05-27T19:24:15Zd5a691646721e41fa192b8980391eaf555cab31c580d81e3c05b528fd704117f
AI chatbotAI securityAnthropic ClaudeBTMOBCrates.ioGitea','SharePoint','Ghost CMS','Drupal','LiteSpeed cPanel','CVEGlassWormGrandoreiroLaravel-LangLazarusMFA prompt bombingPackagistPyPIRATRemotePETrapDoorbanking trojancredential theftcryptojackingexfiltrationexploitmalwarenpmsupply chainvulnerability

What happened

A batch of active cyberthreats and supply-chain incidents affecting Windows, Android, cloud AI workflows and developer ecosystems were reported. Researchers observed banking trojans Grandoreiro and BTMOB targeting organizations and mobile users in Latin America and Europe, and Lazarus using a memory-only RemotePE RAT against financial/crypto firms. Multiple software supply-chain campaigns (TrapDoor, GlassWorm, Packagist, Laravel-Lang) abused npm/PyPI/Crates/Packagist to distribute credential-stealers and malware; a malicious npm package was also found exfiltrating files from Anthropic Claude’s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
d5a691646721e41fa192b8980391eaf555cab31c580d81e3c05b528fd704117f
Enrichment time
2026-05-27T19:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.