Cybersecurity firms have identified a massive surge in advanced banking trojans, including Manic, Grandoreiro, and ToxicPanda 2.0, which target financial institutions and mobile users globally.
- Manic malware combines spyware and banking trojan capabilities, targeting Ukraine, Russia, and Europe.
- Grandoreiro continues to evolve, using legitimate software like Duplicate Files Finder to evade detection in Latin America.
- ToxicPanda 2.0 has expanded its reach to 350+ financial apps and is active in 16 countries, including India.
Cybersecurity companies this week issued critical warnings regarding new and updated banking trojans designed to compromise users worldwide. These sophisticated malware strains enable attackers to phish credentials, harvest sensitive data, and gain remote control over infected devices.
Manic: The Spyware-Trojan Hybrid
ThreatFabric has detailed the emergence of Manic, an Android-based malware that merges banking trojan functionalities with advanced spyware capabilities. While it has primarily targeted Ukraine—including banks and government services—it has also been observed attacking Russian and European financial institutions, as well as cryptocurrency and fintech services.
A standout feature of Manic is its offline mesh relay capability. This allows collected data to be transmitted through nearby infected devices via Wi-Fi Direct or Bluetooth when direct command-and-control (C2) access is unavailable, making it incredibly difficult to intercept.
Why This Matters
BozokMedia analysis shows that the convergence of spyware and banking trojans represents a shift toward total device dominance, where attackers seek not just money, but complete surveillance of the victim.
The integration of offline data relay mechanisms marks a significant escalation in the stealth capabilities of modern mobile malware.
Grandoreiro: A Decade of Evasion
The Acronis Threat Research Unit warned that Grandoreiro, a Windows malware of Brazilian origin, remains a persistent threat. Despite years of law enforcement efforts, it continues to improve. Recent campaigns show a heavy focus on Mexico and Latin America.
To avoid detection, Grandoreiro now abuses legitimate applications like Duplicate Files Finder (DFF) through DLL sideloading. It also employs extensive anti-analysis techniques, such as sandbox detection and environment profiling, to evade automated security systems.
ToxicPanda 2.0: Massive Expansion
Mobile security firm Zimperium has highlighted the evolution of ToxicPanda 2.0. This updated Android trojan has seen a massive leap in scale, moving from targeting 16 applications to nearly 350 financial applications.
The malware is currently targeting financial institutions across 16 countries, including India, Pakistan, South Africa, Mexico, and Nigeria. Notably, attackers are now leveraging cloud infrastructure, specifically Amazon AWS-hosted buckets, to distribute the malware, making the delivery process more resilient.
| Malware Name | Primary Platform | Key Target Region | Primary Method |
|---|---|---|---|
| Manic | Android | Ukraine, Russia, Europe | Spyware/Mesh Relay |
| Grandoreiro | Windows | Latin America, Mexico | DLL Sideloading |
| ToxicPanda 2.0 | Android | Global (incl. India) | Cloud-hosted/App Targeting |
Frequently Asked Questions
Q1: How can I identify if my device is infected?
A1: Look for unusual battery drain, unexpected device reboots, or unauthorized apps appearing on your device.
Q2: Is my banking information safe if I use Two-Factor Authentication (2FA)?
A2: While 2FA adds a layer of security, advanced trojans like Manic can sometimes intercept SMS or notification-based codes.