Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Cybersecurity companies have sounded the alarm about a trio of highly sophisticated banking trojans that are targeting users worldwide, with alarming ease. These malware programs can not only siphon sensitive user data and phish credentials but also grant their operators remote control over compromised devices.

One of these trojans is called Manic, an Android malware that’s been used to target Ukraine, Russia, Europe, and even military-focused messaging apps. But what sets Manic apart from other banking trojans is its unique blend of capabilities: it can log keystrokes, display phishing screens, and even remotely control the device for banking and cryptocurrency fraud. And if that weren’t enough, Manic also includes spyware features like notification monitoring, location tracking, file harvesting, and remote device surveillance.

The malware’s designers have cleverly incorporated an “offline mesh relay” capability, which allows collected data to be shared between nearby infected devices over Wi-Fi Direct or Bluetooth when direct communication with the operator is unavailable. This means that even if a user manages to block the trojan’s communications, it can still quietly exchange sensitive information with other compromised devices.

Another banking trojan on the radar is Grandoreiro, which has been around for over a decade and continues to evolve despite law enforcement efforts to disrupt it. The malware targets users in Latin America, Europe, North America, and even Mexico specifically. What’s particularly concerning about Grandoreiro is its ability to blend in with regular software activity by abusing the legitimate Duplicate Files Finder application through DLL sideloading.

The operators behind this trojan have also prioritized avoiding detection, incorporating extensive anti-analysis functionality into their malware. This includes sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling – all designed to evade automated analysis systems.

Lastly, an updated version of the Android banking trojan ToxicPanda has emerged, targeting financial institutions across 16 countries. The latest variant introduces significant changes, including support for a staggering 167 remote commands and a target list of nearly 350 financial applications. To make matters worse, this new campaign reveals a shift in distribution methods, with samples being delivered through Amazon AWS-hosted buckets – indicating the attackers are leveraging cloud infrastructure to spread their malware.

These banking trojans pose a significant threat to users worldwide, demonstrating just how far cybercriminals will go to exploit vulnerabilities and siphon sensitive information. As such, it’s essential for individuals and organizations alike to prioritize cybersecurity measures, from using robust antivirus software to practicing safe online habits – including avoiding suspicious links, never installing untrusted apps, and regularly updating operating systems and software.

By staying vigilant and informed about the latest threats, we can better protect ourselves against these sophisticated attacks. Remember: in today’s digital landscape, security is not just a concern but an ongoing responsibility that requires constant attention and awareness.


Source: SecurityWeek — 2026-08-22