Skip to main content

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active

5 min read Runtime Rebel Intel
Primary source: securityweek.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: Manic, Grandoreiro, and ToxicPanda 2.0 banking trojans are actively stealing financial credentials and data from global users.
  • Affected systems: Android and Windows devices are targeted, primarily in Europe, Latin America, and emerging markets.
  • Remediation: Implement multi-factor authentication and regularly update operating systems and security software.

Advertisement

Cybersecurity firms have recently highlighted the ongoing and evolving threats posed by several prominent banking trojans: Manic, Grandoreiro, and ToxicPanda 2.0. These malware families are designed to phish credentials, exfiltrate sensitive user data, and enable remote control over compromised devices, primarily targeting financial institutions and their customers worldwide. Their continued activity underscores the persistent danger to personal and corporate finances, demanding vigilant defense strategies from security professionals, as detailed in a recent SecurityWeek report.

Key Banking Trojan Campaigns

The intelligence shared by ThreatFabric, Acronis, and Zimperium reveals distinct characteristics and targeting profiles for each of these active threats.

Manic Android Banking Trojan Analysis

ThreatFabric has provided detailed insights into Manic, an Android malware combining banking trojan and spyware functionalities. This sophisticated threat has primarily been observed targeting users in Ukraine, including banks, government services, and messaging applications. However, its scope extends to Russian and European financial institutions, global cryptocurrency and fintech services, and even military-focused messaging apps.

Manic is distributed through malicious websites and dropper applications. Once installed, it can log keystrokes, display phishing overlays to steal credentials, and allow attackers to remotely control the compromised phone for fraudulent banking and cryptocurrency transactions. Beyond its banking fraud capabilities, Manic incorporates extensive spyware features, such as notification monitoring, location tracking, file harvesting, and remote device surveillance. A particularly notable feature is its offline mesh relay capability, which facilitates data exfiltration via Wi-Fi Direct or Bluetooth among nearby infected devices when direct command-and-control (C2) communication is unavailable. Security teams researching Manic Android banking trojan detection should focus on network anomalies related to peer-to-peer communication and unusual app permissions.

Grandoreiro’s Continued Activity and Evasion Tactics

The Acronis Threat Research Unit has warned that the Grandoreiro banking trojan remains highly active, primarily focusing its attacks on users in Latin America, with a recent campaign significantly targeting Mexico. While Grandoreiro, a Windows-based malware of Brazilian origin, has been active for a decade and previously targeted Europe and North America, its operators consistently refine its capabilities to evade detection. Law enforcement efforts to disrupt its operations have not deterred its evolution.

Recent Grandoreiro samples exhibit advanced evasion techniques, including the abuse of legitimate applications for malicious code execution. Specifically, it leverages the Duplicate Files Finder (DFF) application to perform DLL sideloading, allowing the malware to blend with normal software activity and bypass traditional security measures. The initial infection stages incorporate extensive anti-analysis functionality, such as sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling. These checks occur before any attempt to contact the C2 infrastructure, indicating a high priority for evasion. Understanding Grandoreiro DLL sideloading mitigation is crucial for defenders, requiring diligent application whitelisting and monitoring for suspicious DLL loads.

ToxicPanda 2.0: Expanded Capabilities and Reach

Mobile security firm Zimperium has issued an alert regarding an updated variant, ToxicPanda 2.0, an Android banking trojan primarily targeting Europe. This latest version introduces significant enhancements, including support for 167 remote commands and an expanded target list of nearly 350 financial applications, a substantial increase from the previous version’s 16 targets. ToxicPanda 2.0 now aims at financial institutions across 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama.

One of the most concerning new features is an automated click-based mechanism that abuses Android Wireless Debugging (ADB), enabling privilege escalation and shell-level access on compromised devices. This significantly amplifies the malware’s control over affected systems. Furthermore, the updated campaign reveals a shift in distribution methods, with ToxicPanda 2.0 samples being delivered through Amazon AWS-hosted buckets, indicating attackers are leveraging cloud infrastructure for malware delivery. Organizations focused on ToxicPanda 2.0 Android malware detection should monitor for unusual ADB activity and suspicious downloads from cloud storage services.

How to Defend Against Banking Trojans

To effectively combat threats like Manic, Grandoreiro, and ToxicPanda 2.0, security professionals must prioritize a multi-layered defense strategy:

  • Implement Multi-Factor Authentication (MFA): MFA significantly reduces the risk of account compromise even if credentials are stolen by phishing or keylogging.
  • Regular Software Updates: Ensure all operating systems, applications, and security software (antivirus, EDR) are kept up-to-date. This helps patch known vulnerabilities that malware might exploit.
  • Security Awareness Training: Educate users about phishing tactics, suspicious links, and the dangers of downloading applications from unofficial sources, especially for Android devices.
  • Endpoint Detection and Response (EDR): Deploy EDR solutions capable of detecting advanced malware behaviors, such as DLL sideloading, anti-analysis checks, and unusual process activity.
  • Network Monitoring: Monitor network traffic for suspicious C2 communications, data exfiltration attempts, and anomalous activity, especially from mobile devices or workstations.
  • Application Whitelisting: For Windows environments, consider implementing application whitelisting to prevent unauthorized executables and DLLs from running.
  • Review Mobile Device Permissions: Regularly audit permissions granted to applications on mobile devices and restrict unnecessary access to sensitive data or functions.

Related: Grandoreiro and BTMOB RAT Campaigns Target Windows and Android Users, Rokarolla Android Malware Targets 217 Financial Apps

Advertisement

Advertisement