WatchGuard Blog

What Campaigns Like Grandoreiro Teach Us About Threat Detection

Why do some threats go unnoticed? Discover how connecting scattered signals can help identify an attack before it progresses.

The recent Grandoreiro campaign detected by the WatchGuard Threat Lab team is a clear example of how today’s threats combine different techniques to make detection more difficult and operate more discreetly.

In this case, the attack begins with a phishing email designed to persuade the user to click a link. From there, the victim is taken through several redirects and eventually downloads a compressed file from well-known services such as Dropbox or MediaFire. When the file is opened, a script is executed that initiates the next stages of the infection and uses legitimate applications installed on the device to load malicious components.

This approach helps the threat go unnoticed because each action may appear routine or insignificant when viewed in isolation. It is the relationship between all these actions that makes it possible to recognize the sequence.

The way this banking trojan operates offers a lesson that extends beyond this particular campaign: today’s threats are rarely identified through a single, clear-cut alert. To recognize them before they progress, it is necessary to understand the context in which each action takes place, even when the components involved change or are hidden among legitimate activity.

When Each Tool Sees Only One Part

In today’s campaigns, activity is distributed across different points in the environment. In many cases, each security tool knows what is happening within its own area of visibility, but that information may not be sufficient on its own to determine that a compromise has occurred.

When security controls operate in isolation, the same attack chain can appear to be a collection of unrelated incidents. The email platform generates an alert about a suspicious message, endpoint protection records an anomalous process, the network identifies an unusual connection, and the identity tool flags an unexpected login. If these events are not associated with the same user, device, and timeframe, the analyst must reconstruct the relationship manually.

This fragmentation also affects risk assessment. Each alert may be assigned a low priority because it represents only a limited part of what happened, even though the overall picture reveals a clear progression from initial access to execution. At the same time, analysts have to switch between tools, review logs with different structures, and determine whether the timestamps, users, processes, and devices match. As a result, the time spent gathering context delays containment decisions and diverts attention from other incidents.

From Scattered Signals to a Recognizable Compromise

Determining whether a real compromise has occurred requires a unified view of what is happening across the environment. This requires layered visibility, allowing activity to be observed from different points and those perspectives to be brought together to understand how a threat is progressing. Email provides insight into the origin of an interaction; web activity shows the destinations visited and downloads; the endpoint reveals the processes, scripts, and modules executed; the network records subsequent communications; and identity information helps determine which account was involved and what actions it performed.

When multiple signals coincide around the same user, device, process, destination, or timeframe, they take on a different meaning. A download from a well-known service or the execution of a legitimate application may appear to be routine activity. However, if they occur after the user has accessed a suspicious link and are followed by an unusual connection, the overall sequence warrants greater attention.

Behavior-based detection, in turn, makes it possible to identify these relationships even when the specific components of an attack change. A legitimate application can be used for malicious purposes if it loads modules from unusual locations, starts processes with which it does not normally interact, or establishes communications unrelated to its typical behavior. In these cases, the anomaly does not lie in a single action, but in the way multiple actions occur and connect with one another.

In addition, the sequence may unfold through events separated by minutes, hours, or even days. This is where continuous monitoring becomes particularly important, as it allows new signals to be incorporated and the risk level to be updated as more information emerges, without interpreting a pause in activity as the disappearance of the threat.

Ultimately, campaigns such as Grandoreiro confirm that detection effectiveness cannot be measured solely by the ability to identify a known signal. As attacks distribute their activity across different layers, rely on legitimate tools, and adapt their behavior to the environment, it becomes increasingly important to reconstruct the complete sequence and track its evolution over time. The difference between activity that goes unnoticed and an early response increasingly lies in the ability to connect weak signals before the attacker establishes a foothold. This unified view is what makes it possible to turn scattered signals into actionable decisions and intervene more precisely before the compromise progresses.