Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
New and updated banking trojans Manic, Grandoreiro, and ToxicPanda 2.0 are targeting users globally.
Summary
Cybersecurity firms have detailed new and updated banking trojans: Manic, an Android malware with spyware capabilities targeting Ukraine and other regions; Grandoreiro, a decade-old Windows trojan focusing on Latin America and Europe with advanced anti-analysis features; and ToxicPanda 2.0, an Android banking trojan with expanded command support and targets, now distributed via AWS.
Full text
Cybersecurity companies this week shared information about new and updated banking trojans targeting users worldwide. These types of malware can enable their operators to phish credentials, steal sensitive user data, and remotely control compromised devices. Manic ThreatFabric has detailed Manic, described as an Android malware that combines banking trojan and spyware capabilities. The malware has mainly been used against Ukraine, including banks, government services, and messaging applications. However, it has also been observed targeting Russian and European financial institutions, global cryptocurrency and fintech services, and military-focused messaging apps. Distributed via malicious websites and droppers, the malware enables attackers to log keystrokes, display phishing screens, and remotely control the compromised phone for banking and cryptocurrency fraud. In addition, Manic includes spyware capabilities such as notification monitoring, location tracking, file harvesting, and remote device surveillance.Advertisement. Scroll to continue reading. “A particularly distinctive capability is its offline mesh relay, which allows collected data to move through nearby infected devices over Wi-Fi Direct or Bluetooth when direct C2 access is unavailable,” ThreatFabric noted. Grandoreiro The Acronis Threat Research Unit warned that the Grandoreiro banking trojan remains active, continuing to focus on users in Latin America. Grandoreiro was also seen targeting Europe last year, and it continues to target Europe alongside North America. However, a recent campaign monitored by Acronis saw the bulk of attacks aimed at Mexico. The Windows malware, of Brazilian origin, has been around for a decade, and it has continued to improve despite law enforcement’s attempts to disrupt it. Recent samples abuse the legitimate Duplicate Files Finder (DFF) application to execute malicious code through DLL sideloading. This allows the malware to blend with regular software activity and avoid detection. “The initial sample incorporates extensive anti-analysis functionality, including sandbox detection, virtual machine artifact checks, process blacklisting and environment profiling designed to evade automated analysis systems,” Acronis explained. “These checks are performed before any attempt to contact the command-and-control (C2) infrastructure, suggesting that avoiding analysis is a high priority for the operators.” ToxicPanda 2.0 Mobile security firm Zimperium has issued a warning over an updated variant of ToxicPanda, which is known to mainly target Europe. The Android banking trojan’s latest version introduces significant changes, including support for 167 remote commands and a target list of nearly 350 financial applications; previous versions targeted only 16 apps. ToxicPanda 2.0 is designed to target financial institutions across 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama. “The malware also introduces an automated click-based mechanism to abuse Android Wireless Debugging (ADB), enabling privilege escalation and shell-level access on compromised devices,” Zimperium explained. It added, “The updated campaign also reveals a shift in distribution methods, with ToxicPanda 2.0 samples being delivered through Amazon AWS-hosted buckets, indicating the attackers are leveraging cloud infrastructure for malware delivery.” Related: Rust Supply Chain Attack Linked to North Korean Hackers Related: AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions Related: Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Hackers Target Zimbra Servers in Active Exploitation CampaignOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesHackers Using AI to Target Siemens PLCs in Critical US SectorsCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignCareCloud Data Breach Impact Grows to 3.7 Million IndividualsFortinet Acquires AI Security Company Virtue AIIrregular Details How a Naming Error Let AI Models Attack a Real Company Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware Latest News Former NSA Director Paul Nakasone Launches National Security Advisory FirmIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused BugEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiNew Phishing Toolkit Uses Passkeys to Maintain Access After Password ResetsCritical Isolated-vm Vulnerability Leads to RCE on HostRust Supply Chain Attack Linked to North Korean HackersContractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindMicrosoft Patches Exploited Entra ID Vulnerability Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveWISeKey has appointed Alexander Hirsch as Group Chief Marketing Officer.UltraViolet Cyber has named Andrew Park Chief Information Security Officer.Glow has appointed Patti Degnan as Chief Information Security Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — Manic
- malware — Grandoreiro
- malware — ToxicPanda 2.0