Manic, Grandoreiro and ToxicPanda 2.0 Highlight Continuing Banking Trojan Activity

Security researchers are tracking fresh activity involving three banking trojans—Manic, Grandoreiro and ToxicPanda 2.0—that demonstrate how financially motivated malware continues to evolve across mob...

Security researchers are tracking fresh activity involving three banking trojans—Manic, Grandoreiro and ToxicPanda 2.0—that demonstrate how financially motivated malware continues to evolve across mobile and desktop platforms. The threats can steal credentials and personal information, display fraudulent login pages and give attackers remote control of infected devices.

Manic combines fraud and surveillance

ThreatFabric described Manic as an Android threat that pairs banking-trojan functions with extensive spyware features. Most observed activity has focused on Ukraine, including financial institutions, government services and messaging platforms. Researchers have also identified targeting involving Russian and European banks, cryptocurrency and fintech services, and applications used by military communities.

Manic has been distributed through malicious websites and downloader applications. Its capabilities include keystroke logging, phishing overlays, notification monitoring, location tracking, file collection and remote surveillance. A notable feature is an offline relay mechanism that can use Wi-Fi Direct or Bluetooth to pass stolen information between nearby infected devices when the malware cannot reach its command-and-control server.

Grandoreiro maintains a broad campaign

The Acronis Threat Research Unit reported that the long-running Grandoreiro operation remains active, with Mexico accounting for most victims in a recently analyzed campaign. The Windows banking trojan, which originated in Brazil, has also continued to affect targets in other parts of Latin America, Europe and North America despite previous law-enforcement disruption efforts.

Recent samples misuse the legitimate Duplicate Files Finder application to load malicious code through DLL sideloading. The malware also performs extensive checks for sandboxes, virtual machines, prohibited processes and other analysis indicators before contacting its command-and-control infrastructure, complicating automated investigation.

ToxicPanda expands its reach

Zimperium said ToxicPanda 2.0 represents a substantial update to the Android banking trojan. The new version supports 167 remote commands and contains a list of almost 350 financial applications, compared with 16 in earlier versions. Its target scope spans institutions in 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia and Panama.

The variant reportedly uses automated screen interactions to exploit Android Wireless Debugging and obtain shell-level access. Researchers also observed samples hosted in Amazon Web Services buckets, suggesting that the operators are using cloud infrastructure to distribute the malware.