<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Banking Trojan</title><description>Cybersecurity articles tagged #Banking Trojan on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Grandoreiro Banking Trojan: New Evasion Tactics in Mexico</title><link>https://runtimerebel.com/blog/grandoreiro-banking-trojan-new-evasion-tactics-in-mexico</link><guid isPermaLink="true">https://runtimerebel.com/blog/grandoreiro-banking-trojan-new-evasion-tactics-in-mexico</guid><description>Grandoreiro banking Trojan resurfaces in Mexico, employing advanced evasion tactics after a law enforcement takedown to target financial users.</description><pubDate>Mon, 24 Aug 2026 08:39:06 GMT</pubDate><category>Grandoreiro</category><category>Banking Trojan</category><category>Malware</category><category>Mexico</category><category>Phishing</category></item><item><title>Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active</title><link>https://runtimerebel.com/blog/banking-trojans-manic-grandoreiro-toxicpanda-2-0-active</link><guid isPermaLink="true">https://runtimerebel.com/blog/banking-trojans-manic-grandoreiro-toxicpanda-2-0-active</guid><description>New and updated banking trojans Manic, Grandoreiro, and ToxicPanda 2.0 are actively targeting financial users globally, stealing credentials and data.</description><pubDate>Sat, 22 Aug 2026 16:14:50 GMT</pubDate><category>Banking Trojan</category><category>Grandoreiro</category><category>Android Malware</category><category>Manic</category><category>ToxicPanda</category></item><item><title>Brazilian Banking Trojan Expansion into Portugal Targets Businesses</title><link>https://runtimerebel.com/blog/brazilian-banking-trojan-expansion-into-portugal-targets-businesses</link><guid isPermaLink="true">https://runtimerebel.com/blog/brazilian-banking-trojan-expansion-into-portugal-targets-businesses</guid><description>Portuguese businesses face increased risk from Brazilian banking trojans leveraging shared language for phishing and credential theft.</description><pubDate>Thu, 23 Jul 2026 10:27:20 GMT</pubDate><category>Banking Trojan</category><category>Portugal</category><category>Grandoreiro</category><category>Financial Crime</category><category>Phishing</category></item><item><title>SCMBANKER Malware: Analyzing ClickFix Lures Targeting Mexican Banks</title><link>https://runtimerebel.com/blog/scmbanker-malware-analyzing-clickfix-lures-targeting-mexican-banks</link><guid isPermaLink="true">https://runtimerebel.com/blog/scmbanker-malware-analyzing-clickfix-lures-targeting-mexican-banks</guid><description>Elastic Security Labs tracks REF6045, deploying SCMBANKER malware via fake ClickFix CAPTCHA pages to compromise Mexican banking users.</description><pubDate>Wed, 08 Jul 2026 14:14:47 GMT</pubDate><category>SCMBANKER</category><category>REF6045</category><category>Banking Trojan</category><category>Mexico</category><category>ClickFix</category><category>Phishing</category></item><item><title>Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users</title><link>https://runtimerebel.com/blog/ousaban-banking-trojan-phishing-lures-target-iberian-bank-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/ousaban-banking-trojan-phishing-lures-target-iberian-bank-users</guid><description>Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.</description><pubDate>Wed, 01 Jul 2026 16:53:05 GMT</pubDate><category>Ousaban</category><category>Banking Trojan</category><category>Phishing</category><category>Spain</category><category>Portugal</category><category>Windows</category><category>Financial Crime</category><category>Malware Analysis</category></item><item><title>Rokarolla Android Malware Targets 217 Financial Apps</title><link>https://runtimerebel.com/blog/rokarolla-android-malware-targets-217-financial-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/rokarolla-android-malware-targets-217-financial-apps</guid><description>New Rokarolla Android banking trojan targets 217 financial and crypto applications. Learn its TTPs and how to protect mobile banking apps from malware.</description><pubDate>Tue, 16 Jun 2026 21:08:26 GMT</pubDate><category>Rokarolla</category><category>Android Malware</category><category>Banking Trojan</category><category>Mobile Security</category><category>Financial Services</category><category>Overlay Attack</category></item><item><title>Grandoreiro and BTMOB RAT Campaigns Target Windows and Android Users</title><link>https://runtimerebel.com/blog/grandoreiro-and-btmob-rat-campaigns-target-windows-and-android-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/grandoreiro-and-btmob-rat-campaigns-target-windows-and-android-users</guid><description>Analysis of Grandoreiro and BTMOB malware campaigns targeting financial sectors in Spain, Portugal, and Latin America through Windows and Android platforms.</description><pubDate>Wed, 27 May 2026 17:11:44 GMT</pubDate><category>Grandoreiro</category><category>BTMOB</category><category>Banking Trojan</category><category>Android Malware</category><category>ESET</category><category>WatchGuard</category></item><item><title>TrickMo Android Trojan Uses TON Blockchain for Covert C2</title><link>https://runtimerebel.com/blog/trickmo-android-trojan-uses-ton-blockchain-for-covert-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/trickmo-android-trojan-uses-ton-blockchain-for-covert-c2</guid><description>TrickMo Android banking malware adopts The Open Network (TON) blockchain for decentralized C2, targeting European users via accessibility service abuse.</description><pubDate>Mon, 11 May 2026 09:18:04 GMT</pubDate><category>Trickmo</category><category>Android Malware</category><category>TON Blockchain</category><category>Banking Trojan</category><category>Fintech Threats</category></item><item><title>TCLBANKER Malware: Brazilian Trojan Spreads via WhatsApp and Outlook</title><link>https://runtimerebel.com/blog/tclbanker-malware-brazilian-trojan-spreads-via-whatsapp-and-outlook</link><guid isPermaLink="true">https://runtimerebel.com/blog/tclbanker-malware-brazilian-trojan-spreads-via-whatsapp-and-outlook</guid><description>TCLBANKER (REF3076) targets 59 financial platforms using the SORVEPOTEL worm. Learn how to detect and mitigate this evolving Brazilian banking trojan.</description><pubDate>Fri, 08 May 2026 20:27:32 GMT</pubDate><category>TCLBANKER</category><category>REF3076</category><category>SORVEPOTEL</category><category>Banking Trojan</category><category>Financial Fraud</category></item><item><title>TCLBanker Malware Targets Fintech via WhatsApp and Outlook</title><link>https://runtimerebel.com/blog/tclbanker-malware-targets-fintech-via-whatsapp-and-outlook</link><guid isPermaLink="true">https://runtimerebel.com/blog/tclbanker-malware-targets-fintech-via-whatsapp-and-outlook</guid><description>TCLBanker malware uses trojanized Logitech AI installers to target 59 banking apps and spreads automatically via WhatsApp and Outlook messages.</description><pubDate>Fri, 08 May 2026 05:05:17 GMT</pubDate><category>TCLBANKER</category><category>Logitech AI Prompt Builder</category><category>Banking Trojan</category><category>WhatsApp Malware</category><category>Outlook Propagation</category></item><item><title>Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America</title><link>https://runtimerebel.com/blog/casbaneiro-banking-trojan-evasion-and-lateral-movement-in-latin-america</link><guid isPermaLink="true">https://runtimerebel.com/blog/casbaneiro-banking-trojan-evasion-and-lateral-movement-in-latin-america</guid><description>Analyzing Casbaneiro, a sophisticated banking Trojan employing advanced evasion, process injection, and network worming to target financial institutions and users in…</description><pubDate>Thu, 02 Apr 2026 16:28:48 GMT</pubDate><category>Casbaneiro</category><category>Banking Trojan</category><category>Latin America</category><category>Augmented Marauder</category><category>Financial Fraud</category><category>Phishing</category><category>Lateral Movement</category></item><item><title>Perseus Android Banking Malware Targets Notes Apps for Data Theft</title><link>https://runtimerebel.com/blog/perseus-android-banking-malware-targets-notes-apps-for-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/perseus-android-banking-malware-targets-notes-apps-for-data-theft</guid><description>Researchers discover Perseus, a new Android banking malware evolved from Cerberus, targeting notes apps to facilitate device takeover and financial fraud.</description><pubDate>Thu, 19 Mar 2026 16:24:30 GMT</pubDate><category>Perseus Malware</category><category>Android Malware</category><category>Banking Trojan</category><category>Cerberus</category><category>Financial Fraud</category></item><item><title>VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks</title><link>https://runtimerebel.com/blog/venon-malware-rust-based-banking-trojan-targets-brazilian-banks</link><guid isPermaLink="true">https://runtimerebel.com/blog/venon-malware-rust-based-banking-trojan-targets-brazilian-banks</guid><description>A new Rust-based malware called VENON is targeting 33 Brazilian banks with credential-stealing overlays, signaling a shift in Latin American cybercrime TTPs.</description><pubDate>Thu, 12 Mar 2026 20:12:38 GMT</pubDate><category>VENON</category><category>Banking Trojan</category><category>Rust</category><category>Brazil</category><category>Credential Theft</category></item></channel></rss>