Breaking
SecurityDeveloping Story

Banking Trojans Evolve With New Tricks

Manic, Grandoreiro, and ToxicPanda 2.0 show how banking malware is becoming more sophisticated.

··2 hours ago·3 min read
black and red laptop computer
Photo by FlyD on Unsplash

This week, cybersecurity researchers pulled back the curtain on three separate banking trojans, each showing new levels of skill and ambition. From an Android malware that can silently relay stolen data through nearby phones to a Windows trojan that hides inside a legitimate app, these threats highlight the evolving tactics of financial cybercriminals.

Manic: A New Android Threat

ThreatFabric has detailed a new Android malware called Manic, which combines the abilities of a banking trojan with spyware. According to the firm, the malware has primarily targeted Ukraine, going after banks, government services, and messaging apps.

But its reach extends beyond Ukraine. ThreatFabric reports that Manic has also been observed hitting Russian and European financial institutions, global cryptocurrency and fintech services, and military-focused messaging apps. The malware is distributed through malicious websites and droppers, giving attackers the ability to log keystrokes, display phishing screens, and remotely control the compromised phone for banking and cryptocurrency fraud.

What makes Manic stand out is its spyware features: it can monitor notifications, track the device's location, harvest files, and even conduct remote surveillance. Perhaps most notably, it includes an offline mesh relay that lets stolen data hop through nearby infected devices over Wi-Fi Direct or Bluetooth when a direct connection to the command-and-control server is unavailable. This clever workaround keeps the data flowing even when the internet connection is cut.

“A particularly distinctive capability is its offline mesh relay, which allows collected data to move through nearby infected devices over Wi-Fi Direct or Bluetooth when direct C2 access is unavailable,”

— noted ThreatFabric in their analysis.

Grandoreiro: Windows Malware Persists

The Acronis Threat Research Unit has warned that the Grandoreiro banking trojan remains active, with a continued focus on users in Latin America. Last year, it was seen targeting Europe, and it continues to target Europe alongside North America. However, a recent campaign monitored by Acronis saw the bulk of attacks aimed at Mexico.

This Windows malware, which has Brazilian origins, has been around for a decade and has kept improving despite law enforcement's attempts to disrupt it. Recent samples abuse a legitimate application called Duplicate Files Finder (DFF) to execute malicious code through DLL sideloading. This technique lets the malware blend in with normal software activity, making it harder to detect.

Acronis explains that the initial sample includes extensive anti-analysis features, such as sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling designed to evade automated analysis systems. These checks are performed before any attempt to contact the command-and-control (C2) infrastructure, suggesting that avoiding analysis is a high priority for the operators.

ToxicPanda 2.0: A Major Upgrade

Mobile security firm Zimperium has issued a warning about an updated variant of ToxicPanda, an Android banking trojan known to mainly target Europe. The latest version introduces significant changes, including support for 167 remote commands and a target list of nearly 350 financial applications. In contrast, previous versions only targeted 16 apps.

ToxicPanda 2.0 is designed to target financial institutions across 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama.

Zimperium notes that the malware also introduces an automated click-based mechanism to abuse Android Wireless Debugging (ADB), enabling privilege escalation and shell-level access on compromised devices. This is a powerful capability for attackers.

Zimperium added, “The updated campaign also reveals a shift in distribution methods, with ToxicPanda 2.0 samples being delivered through Amazon AWS-hosted buckets, indicating the attackers are leveraging cloud infrastructure for malware delivery.”

Key Numbers at a Glance

  • 167 remote commands supported by ToxicPanda 2.0
  • Nearly 350 financial applications targeted by ToxicPanda 2.0
  • 16 countries targeted by ToxicPanda 2.0
  • Previous ToxicPanda versions targeted only 16 apps

Why It Matters

These three trojans show how banking malware is becoming more sophisticated. Manic's offline mesh relay and spyware features could make it harder to track stolen data, while Grandoreiro's DLL sideloading and anti-analysis checks show a focus on staying hidden. ToxicPanda's expanded scope and use of cloud infrastructure suggest attackers are adapting to new defenses.

For users and financial institutions, this means staying alert to the latest threats and updating security measures accordingly. The evolution of these trojans indicates that banking malware remains a serious and persistent threat.

#banking trojans#manic#grandoreiro#toxicpanda#android malware

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories