Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Hit New Targets

Three sophisticated banking trojans—Manic, Grandoreiro, and ToxicPanda 2.0—are expanding their reach with advanced evasion techniques.

By Central
Manic uses offline mesh relays, Grandoreiro persists after a decade, and ToxicPanda 2.0 targets 350 apps.
Highlights
  • Manic combines banking fraud with spyware and uses an offline mesh relay system to evade takedowns.
  • Grandoreiro, a decade-old Brazilian banking trojan, remains active and shifts focus to Mexico.
  • ToxicPanda 2.0 expands its target list to 350 apps and uses cloud-hosted malware delivery.

Three major malware campaigns have converged on banking and mobile users across Europe, Latin America, and Asia this week, as cybersecurity researchers detailed the evolution of Android and Windows threats that have grown more sophisticated, more aggressive, and more geographically ambitious. The updates on Manic, Grandoreiro, and ToxicPanda 2.0 illustrate a clear trend: attackers are not just stealing credentials but are building remote-control infrastructure that treats compromised devices as fully owned assets for fraud, surveillance, and data theft.

Manic: A Hybrid Android Threat Combining Banking Fraud with Spyware Capabilities

ThreatFabric has published an analysis of Manic, an Android malware that represents a worrying convergence of two historically separate threat categories: banking trojans and spyware. Manic has primarily been deployed against targets in Ukraine, where it has been observed attacking banks, government services, and messaging applications. But its reach extends much further. The malware has also been found targeting financial institutions in Russia and across Europe, as well as global cryptocurrency platforms, fintech services, and military-focused messaging apps.

How Manic Infects and Operates

Distribution occurs through malicious websites and dropper applications. Once installed, Manic gives attackers the ability to log keystrokes, overlay phishing screens on legitimate banking and messaging apps, and remotely control the compromised phone. This remote-control capability is directly leveraged for banking and cryptocurrency fraud — the attackers do not merely harvest data for later use but actively interact with accounts in real time.

Beyond its trojan functions, Manic includes a full suite of spyware features. It monitors incoming notifications, tracks the device’s physical location, harvests files stored on the phone, and enables remote surveillance of the device environment. These capabilities make it useful for espionage as much as for financial theft.

Offline Mesh Relay: A Distinctive Evasion Technique

A particularly distinctive capability in Manic is its offline mesh relay system. When direct communication with the command-and-control (C2) server is unavailable, the malware can pass collected data through nearby infected devices using Wi-Fi Direct or Bluetooth. This peer-to-peer mesh network allows Manic operators to maintain data exfiltration even when the primary C2 channel is blocked, making takedowns and network-level defenses far less effective.

For users and network defenders, this means a Manic infection is not an isolated incident. Any compromised device becomes a potential relay node, helping the malware survive network segmentation, VPN enforcement, or C2 domain seizures.

Grandoreiro: A Decade-Old Brazilian Banking Trojan Refuses to Fade

The Acronis Threat Research Unit has issued a warning about the continued activity of Grandoreiro, a Windows-based banking trojan of Brazilian origin that has been operational for ten years. Despite law enforcement actions aimed at disrupting its infrastructure, Grandoreiro remains active and is still evolving its evasion techniques.

Geographic Focus Shifts to Mexico

Grandoreiro has historically concentrated on Latin American users, but it was also observed targeting Europe and North America last year. The most recent campaign monitored by Acronis, however, shows a heavy concentration of attacks aimed at Mexico. This geographic targeting is not random — the malware’s operators appear to be following financial opportunity, shifting focus to regions where specific banking platforms and online payment systems are most widely used.

DLL Sideloading and Anti-Analysis Defenses

Recent Grandoreiro samples have adopted a new infection vector by abusing the legitimate Duplicate Files Finder (DFF) application. By placing a malicious dynamic-link library (DLL) in the same directory as the legitimate DFF executable, the attackers achieve DLL sideloading — the benign program loads the malicious code as if it were a legitimate component. This allows Grandoreiro to blend in with regular software activity and evade signature-based detection.

The initial sample also incorporates extensive anti-analysis functionality. Acronis researchers reported that the malware includes sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling — all designed to evade automated analysis systems. Critically, these checks are performed before any attempt to contact the C2 infrastructure, suggesting that the operators place a high priority on avoiding detection during the analysis phase.

This level of defensive engineering means that Grandoreiro infections will often be invisible to automated security tools that rely on behavioral analysis or network traffic inspection at the initial stage. For enterprise security teams, this reinforces the importance of endpoint detection and response (EDR) systems that can identify malicious behavior post-execution.

ToxicPanda 2.0: An Android Banking Trojan Expands Its Reach Dramatically

Zimperium has issued a warning about ToxicPanda 2.0, an updated variant of an Android banking trojan that previously concentrated on European targets. The new version represents a significant escalation in capability and scope.

What Is ToxicPanda 2.0?

ToxicPanda 2.0 is an Android banking trojan designed to steal login credentials and enable fraud against financial applications. The updated variant introduces support for 167 remote commands, giving attackers granular control over the compromised device. Its target list has expanded to include nearly 350 financial applications — a dramatic increase from the 16 apps targeted in previous versions. This expansion alone signals that the operators are investing heavily in maintaining broad compatibility with the global financial app ecosystem.

Geographic Expansion and New Target Countries

ToxicPanda 2.0 is now designed to target financial institutions across 16 countries. The updated list includes Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama, among others. This geographic diversification suggests the operators are following expanding mobile banking adoption in emerging markets, where security awareness and device hygiene may lag behind the rapid rollout of financial apps.

Automated ADB Abuse for Privilege Escalation

One of the most technically interesting features in ToxicPanda 2.0 is an automated click-based mechanism that abuses Android Wireless Debugging (ADB). ADB is a legitimate development tool used for debugging Android apps, but in the hands of malware operators, it provides a pathway to privilege escalation and shell-level access on compromised devices. By automating the process of granting ADB permissions through simulated click sequences, the malware can achieve deep system access without relying on traditional exploit chains.

The implications are significant. Once an attacker has shell-level access, they can install additional malware, modify system files, intercept communications at the OS level, and persist even after factory resets in some cases.

Cloud Infrastructure for Malware Delivery

Zimperium also noted a shift in distribution methods. ToxicPanda 2.0 samples are being delivered through Amazon AWS-hosted buckets. By leveraging legitimate cloud infrastructure, the attackers make it harder for defenders to block malicious downloads using domain reputation or IP blacklists. AWS-hosted delivery also provides scalability — the attackers can spin up new distribution points quickly as old ones are taken down.

For organizations relying on URL filtering or cloud access security brokers (CASBs), this development means that traditional allowlisting of major cloud providers is no longer sufficient. Malicious content can now be distributed from the same infrastructure that hosts legitimate enterprise applications.

How Banking Trojans Evolve: Common Patterns Across Manic, Grandoreiro, and ToxicPanda

While each threat has distinct characteristics, several common patterns emerge from the three reports that are worth highlighting for anyone responsible for organizational or personal security.

Anti-Analysis and Evasion Are the New Baseline

All three malware families demonstrate advanced evasion techniques. Grandoreiro performs sandbox and VM detection before any C2 contact. Manic uses an offline mesh relay to bypass network controls. ToxicPanda 2.0 leverages legitimate cloud infrastructure and development tools. Banking trojan operators are no longer relying on simple obfuscation — they are building multi-layered evasion strategies that anticipate how security researchers and automated tools will respond.

Remote Control Is the Core Feature

The days of banking trojans that simply steal passwords and send them to a drop server are long gone. Manic, Grandoreiro, and ToxicPanda 2.0 all provide extensive remote-control capabilities. Attackers can interact with banking sessions in real time, initiate transfers, approve transactions, and move money before traditional fraud detection systems can respond. This shift from data theft to real-time fraud requires a corresponding shift in defensive strategies — organizations must focus on behavioral detection and transaction anomaly monitoring, not just credential protection.

Geographic Targeting Follows Financial Opportunity

The geographic distribution of these threats is not accidental. Grandoreiro’s shift toward Mexico corresponds with the country’s high mobile banking adoption rates. ToxicPanda 2.0’s expansion into Pakistan, India, Nigeria, and Indonesia mirrors the rapid growth of digital financial services in those markets. Manic’s focus on Ukraine, Russia, and Europe reflects the concentration of cryptocurrency usage and fintech adoption in those regions. Security teams should monitor these threat landscapes not just for the technical indicators of compromise but for strategic intelligence about where attackers are likely to strike next.

For individual users, the single most effective defense remains application source control. Manic, ToxicPanda, and similar Android banking trojans are almost always distributed outside official app stores. Users should install applications only from the Google Play Store — and even then, should scrutinize app permissions carefully. Any app requesting accessibility service permissions, overlay capabilities, or SMS access should be treated with extreme suspicion unless its functionality clearly requires those permissions.

For enterprise security teams, the emergence of offline mesh relays (Manic), DLL sideloading via legitimate applications (Grandoreiro), and cloud-hosted malware delivery (ToxicPanda 2.0) demands a layered defensive approach. Endpoint detection must be supplemented with network traffic analysis, application whitelisting, and strict controls on debug interfaces like ADB for any corporate-managed devices.

For financial institutions specifically, the expansion of target lists to 350 apps (ToxicPanda 2.0) and the integration of real-time device control (Manic and Grandoreiro) mean that mobile banking security can no longer be treated as a separate concern. Fraud detection systems must be capable of incorporating device health signals and behavioral biometrics alongside traditional transaction monitoring.

A Persistent and Evolving Threat Landscape

The concurrent activity of Manic, Grandoreiro, and ToxicPanda 2.0 is not a coincidence but a reflection of the banking trojan ecosystem’s maturation. These are not experimental or amateur operations. They are professionally developed, regularly updated, and operationally sophisticated. The use of legitimate infrastructure, offline communication channels, and multi-layered anti-analysis techniques indicates that their operators have the resources and expertise to sustain long-term campaigns.

The takeaway for the wider security community is that banking trojans are no longer just a Windows problem or a Latin American problem. They are a mobile, cross-platform, global problem that continues to grow in technical sophistication and geographic reach. Defenders must adapt accordingly — not just by updating signatures or blocking known domains, but by fundamentally rethinking how they validate device integrity, monitor user sessions, and respond to real-time fraud.

Share This Article