Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users
2026-05-27T19:24:15Z•d5a691646721e41fa192b8980391eaf555cab31c580d81e3c05b528fd704117f
AI chatbotAI securityAnthropic ClaudeBTMOBCrates.ioGitea','SharePoint','Ghost CMS','Drupal','LiteSpeed cPanel','CVEGlassWormGrandoreiroLaravel-LangLazarusMFA prompt bombingPackagistPyPIRATRemotePETrapDoorbanking trojancredential theftcryptojackingexfiltrationexploitmalwarenpmsupply chainvulnerability
What happened
A batch of active cyberthreats and supply-chain incidents affecting Windows, Android, cloud AI workflows and developer ecosystems were reported. Researchers observed banking trojans Grandoreiro and BTMOB targeting organizations and mobile users in Latin America and Europe, and Lazarus using a memory-only RemotePE RAT against financial/crypto firms. Multiple software supply-chain campaigns (TrapDoor, GlassWorm, Packagist, Laravel-Lang) abused npm/PyPI/Crates/Packagist to distribute credential-stealers and malware; a malicious npm package was also found exfiltrating files from Anthropic Claude’s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d5a691646721e41fa192b8980391eaf555cab31c580d81e3c05b528fd704117f
- Enrichment time
- 2026-05-27T19:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.