Banking Trojans on the Rise: Manic, Grandoreiro, and ToxicPanda 2.0 Threaten Users Worldwide
A new wave of sophisticated banking trojans has emerged, targeting users in various regions worldwide. These malware variants – Manic, Grandoreiro, and an updated version of ToxicPanda – are designed to phish credentials, steal sensitive data, and remotely control compromised devices, posing a significant threat to financial institutions and individuals.
Manic, developed by ThreatFabric, is a particularly concerning Android malware that combines banking trojan and spyware capabilities. While initially used against Ukraine, its operators have expanded their reach to target Russian and European financial institutions, as well as global cryptocurrency and fintech services. Manic’s distributed via malicious websites and droppers, allowing attackers to log keystrokes, display phishing screens, and remotely control the compromised phone for banking and cryptocurrency fraud.
In addition to its trojan capabilities, Manic includes advanced spyware features such as notification monitoring, location tracking, file harvesting, and remote device surveillance. A notable feature is its offline mesh relay, which enables collected data to move through nearby infected devices over Wi-Fi Direct or Bluetooth when direct command-and-control (C2) access is unavailable.
Meanwhile, the Acronis Threat Research Unit has issued a warning about Grandoreiro, a Windows banking trojan that remains active despite law enforcement efforts to disrupt it. This decade-old malware continues to evolve and improve, with recent samples using legitimate software to execute malicious code through DLL sideloading. This tactic allows Grandoreiro to blend with regular software activity and evade detection.
Grandoreiro’s operators have also shifted their focus to targeting users in Latin America, particularly Mexico. The malware has been observed abusing the Duplicate Files Finder (DFF) application to execute malicious code and avoid automated analysis systems. Its initial sample incorporates extensive anti-analysis functionality, including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling designed to evade automated analysis systems.
Zimperium has also issued a warning about an updated version of ToxicPanda, which primarily targets Europe but also poses a threat to financial institutions in 16 countries worldwide. The Android banking trojan’s latest version introduces significant changes, including support for 167 remote commands and a target list of nearly 350 financial applications. Its automated click-based mechanism enables privilege escalation and shell-level access on compromised devices.
ToxicPanda 2.0 also marks a shift in distribution methods, with samples being delivered through Amazon AWS-hosted buckets, indicating the attackers are leveraging cloud infrastructure for malware delivery.
These banking trojans demonstrate the ongoing threat posed by sophisticated malware variants designed to target financial institutions and individuals worldwide. As these threats continue to evolve, it’s essential for users and organizations to remain vigilant and take proactive measures to protect themselves against phishing attacks and other malicious activities.
To stay ahead of these threats, users should exercise caution when downloading software from unknown sources and be wary of suspicious links or attachments. Organizations should implement robust security measures, including regular software updates, anti-virus protection, and employee education on cybersecurity best practices. By being proactive and informed, individuals can reduce their exposure to these malicious attacks and protect themselves against the growing threat of banking trojans.
Source: SecurityWeek — 2026-08-22