Manic, Grandoreiro and ToxicPanda 2.0 Evolve Banking Malware
Security firms this week disclosed updates to Manic, Grandoreiro and ToxicPanda 2.0 that expand credential theft, data exfiltration and remote device control across multiple regions.
Cybersecurity firms this week disclosed updated campaigns and new capabilities for three banking trojans: Manic, Grandoreiro and ToxicPanda 2.0. The reports describe added tools for credential theft, data exfiltration and remote control of compromised devices.
Manic is an Android malware that combines banking trojan and spyware functions and has mainly targeted Ukraine. ThreatFabric reported the malware has also hit Russian and European financial institutions, global cryptocurrency and fintech services, and military-focused messaging apps. Manic is delivered via malicious websites and droppers. Its capabilities include keystroke logging, onscreen phishing overlays, remote control for banking and crypto fraud, notification monitoring, location tracking, file harvesting and persistent device surveillance. ThreatFabric noted an offline mesh relay that moves collected data through nearby infected devices over Wi‑Fi Direct or Bluetooth when direct command and control access is unavailable.
Grandoreiro is a decade-old Windows banking trojan of Brazilian origin that remains active. Acronis Threat Research Unit found a recent campaign focused on Mexico while activity continues across Latin America, Europe and North America. Recent samples abuse a legitimate utility called Duplicate Files Finder to execute malicious code through DLL sideloading, which lets the malware run under the guise of normal software. Acronis observed that initial samples perform extensive anti-analysis checks, including sandbox detection, virtual machine artifact checks, process blacklisting and environment profiling, before attempting contact with command and control infrastructure. The report notes law enforcement disruptions have not ended Grandoreiro operations.
Zimperium flagged an updated ToxicPanda Android trojan labeled ToxicPanda 2.0. The new version supports 167 remote commands and targets nearly 350 financial applications, up from 16 in earlier variants. ToxicPanda 2.0 is configured to target institutions in 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia and Panama. The malware adds an automated click mechanism that abuses Android Wireless Debugging to escalate privileges and obtain shell-level access. Samples in the recent campaign were delivered through Amazon AWS-hosted storage buckets.
The reports identify several technical trends. Mobile banking trojans are incorporating broader spyware features. Windows banking families are using DLL sideloading and stronger anti-analysis measures. Threat actors are leveraging cloud-hosted storage for distribution and device-to-device relays to move data when direct network links are limited.








