[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fT7Jz_GGoHVQXz_OZFoq3azsj5SBW2brdSDdNTIHfm1Q":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"bff93dc4-f315-449a-9570-f2ff0bfa9e1c","banking-trojans-manic-grandoreiro-toxicpanda-20-target-mobile-and-desktop-users","30de7774-603e-4abc-a0c2-23f3d8ca7b6d","Banking Trojans Manic, Grandoreiro & ToxicPanda 2.0 Target Mobile and Desktop Users","A new wave of banking trojans — Manic (Android), Grandoreiro (Windows), and ToxicPanda 2.0 (Android) — are actively targeting financial users across multiple regions, including Ukraine, Latin America, and Europe. These malware families combine credential theft, spyware capabilities, and advanced anti-analysis techniques to evade detection and persist on compromised devices. ToxicPanda 2.0's distribution via AWS infrastructure highlights how threat actors are abusing legitimate cloud services to increase credibility and bypass blocklists. The longevity of Grandoreiro (active for over a decade) underscores the danger of unpatched or unmonitored legacy systems. Without proactive user education, robust mobile device management, and real-time behavioral monitoring, financial institutions and their customers remain highly exposed.","**Immediate actions:**\n- Enforce mobile device management (MDM) policies that restrict sideloading of apps from unofficial sources on all corporate and BYOD devices.\n- Block or scrutinize outbound connections to newly registered or anomalous AWS endpoints using DNS filtering and threat intelligence feeds.\n- Push emergency security advisories to customers warning them of fake banking apps and phishing campaigns tied to these trojans.\n\n**Long-term improvements:**\n- Implement application allowlisting on Windows endpoints to prevent unauthorized executables like Grandoreiro from running.\n- Require regular OS and application patching cycles to eliminate vulnerabilities exploited by long-lived malware families.\n- Adopt a zero-trust architecture that enforces step-up authentication for high-value banking transactions, reducing the impact of credential theft.\n\n**Detection measures:**\n- Deploy mobile threat defense (MTD) solutions capable of detecting Android banking trojan behaviors such as overlay attacks and accessibility service abuse.\n- Enable behavioral analytics and SIEM correlation rules to flag unusual banking session activity, account takeover patterns, or anomalous API calls indicative of trojan activity.\n- Monitor for abuse of cloud infrastructure (e.g., AWS) as malware distribution channels by integrating cloud provider threat feeds into your SOC workflows.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 7 – Continuous Vulnerability Management","CIS Control 9 – Email and Web Browser Protections","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 AC-17 – Remote Access","NIST SP 800-53 RA-5 – Vulnerability Monitoring and Scanning","NIST SP 800-124 – Guidelines for Managing the Security of Mobile Devices","GDPR Article 32 – Security of Processing (for EU-region financial data exposure)","PCI DSS Requirement 5 – Protect All Systems Against Malware","PCI DSS Requirement 6 – Develop and Maintain Secure Systems and Software","ITIL – Threat and Vulnerability Management Practice","published","2026-08-22T10:20:21.959986+00:00","2026-08-22T10:20:21.885+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.securityweek.com\u002Fbanking-trojans-manic-grandoreiro-toxicpanda-2-0-in-the-spotlight\u002F","banking-trojans-manic-grandoreiro-toxicpanda-2-0-in-the-spotlight-2e6889","Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[51,57],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"8eb87960-d227-4605-b400-8f314d4ac31f","2026-08-24","morning","ThreatNoir Morning Brief — August 24","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-24\u002Fthreatnoir-morning-brief-2026-08-24.mp3",{"id":58,"date":59,"edition":60,"title":61,"audio_url":62},"0f0be9d9-ab9b-456b-8dc5-f2c28971ff8d","2026-08-22","afternoon","ThreatNoir Weekend Brief — August 22","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-08-22\u002Fthreatnoir-afternoon-brief-2026-08-22.mp3"]