Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2493+ Articles
160+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Banking Trojans Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight
Banking Trojans Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight
NEWS

Banking Trojans Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight

Three active banking trojans — spyware-laden Manic, persistent Grandoreiro, and an expanded ToxicPanda 2.0 — are targeting banks across Latin America, Europe, and Asia.

Dylan H.

News Desk

August 22, 2026
5 min read

Overview

Security researchers have brought three active banking trojans back into focus this week: Manic, a newly characterized spyware-equipped banking malware; Grandoreiro, a long-running campaign persisting across Latin America and Europe despite law enforcement disruption; and ToxicPanda 2.0, an expanded version of the Android banking trojan that has broadened its targeting to additional countries and banking institutions.

Together they represent the ongoing industrialization of financial fraud malware — each with distinct technical profiles and geographic focuses, but sharing a common goal: stealing banking credentials and authorizing fraudulent transactions.

Manic: Spyware-Equipped Banking Malware

Manic is a newly detailed banking trojan notable for integrating spyware capabilities alongside its core credential-theft functions. Unlike traditional banking malware that focuses narrowly on overlay attacks or keylogging, Manic's spyware component enables:

  • Continuous screen capture and exfiltration — providing operators with real-time visibility into victim activity
  • Contact list and SMS harvesting — useful for SIM-swap support, social engineering of victims' contacts, or bypassing SMS-based two-factor authentication
  • Microphone and camera access — enabling audio/video surveillance in tandem with financial fraud

The combination of espionage and fraud capabilities in a single implant suggests a more sophisticated threat actor with interests beyond a quick account drain — potentially enabling sustained access to high-value targets.

Grandoreiro: Persistent and Resilient

Grandoreiro is one of the most well-documented banking trojans in the wild, originally emerging from Brazil and expanding aggressively through Latin America and Europe. Despite a significant law enforcement operation in early 2024 that led to arrests of key operators, the malware has proven remarkably resilient — new infrastructure and updated variants continue to surface.

Key characteristics of current Grandoreiro campaigns:

  • Phishing-led distribution — spam campaigns impersonating tax authorities, utilities, and financial institutions deliver the initial loader
  • DGA (Domain Generation Algorithm) — Grandoreiro uses a DGA to generate C2 domains, making infrastructure blocking significantly harder for defenders
  • Backdoor functionality — beyond banking fraud, recent variants include remote desktop capabilities and file exfiltration
  • Geographic expansion — campaigns have been observed targeting Spain, Portugal, Argentina, Mexico, and several other countries, reflecting the operators' continued investment in the platform

The persistence of Grandoreiro illustrates how difficult it is to permanently disrupt malware ecosystems when the underlying code and criminal network remain intact.

ToxicPanda 2.0: Broader Targeting, Deeper Capabilities

ToxicPanda debuted in late 2024 as an Android banking trojan targeting primarily Italian and Portuguese-speaking markets. The 2.0 variant analyzed in current research represents a significant evolution:

  • Expanded bank targeting — the new version's target list has grown substantially, now covering institutions in additional European and Asian markets
  • Improved ATS (Automated Transfer System) — ToxicPanda 2.0 has refined its on-device fraud engine, allowing it to automate fund transfers without requiring real-time operator interaction
  • Enhanced evasion — updated code obfuscation and anti-analysis techniques complicate detection by mobile security solutions
  • OTP interception — the malware continues to excel at intercepting one-time passwords delivered via SMS or notification, bypassing standard 2FA

The ATS capability is particularly dangerous: rather than simply stealing credentials for later use, ToxicPanda can complete the full fraud cycle — authenticating, navigating the banking app, and transferring funds — automatically, at scale, in the background while the victim's device appears idle.

Geographic Focus and Target Overlap

TrojanPrimary RegionsDeliveryKey Capability
ManicTBD / emergingLikely phishing/APKSpyware + credential theft
GrandoreiroLatin America, Europe (ES, PT)Phishing emailDGA C2, RDP backdoor
ToxicPanda 2.0Europe, Asia (expanding)Malicious APKAutomated on-device fraud

Defensive Recommendations

For individual users:

  • Only install banking apps from official app stores (Google Play, App Store)
  • Enable Google Play Protect and do not sideload APKs from unknown sources
  • Be suspicious of unsolicited emails or SMS messages impersonating banks, tax agencies, or utilities — do not click embedded links
  • Use a hardware security key or authenticator app for 2FA where available, as these are significantly harder for trojans to bypass than SMS OTPs

For financial institutions:

  • Deploy behavioral biometrics and anomaly detection on mobile banking sessions — unusual navigation patterns or transaction velocity can surface ATS activity
  • Implement transaction risk scoring that factors in device signals (rooting, overlay permissions, unusual accessibility service usage)
  • Consider requiring step-up authentication for high-value transactions, with out-of-band confirmation channels

For security teams:

  • Monitor for indicators of compromise (IoCs) associated with all three families — threat intel feeds from sources tracking Latin American and Android malware are particularly useful here
  • Review mobile app store reviews and abuse reports for signs of overlay or impersonation attacks targeting your institution

Key Takeaway

The simultaneous spotlight on Manic, Grandoreiro, and ToxicPanda 2.0 underscores that the banking trojan ecosystem is not contracting — it is evolving. Spyware integration, automated fraud engines, and persistent operator networks make these threats increasingly difficult to disrupt. Financial institutions and their customers need layered defenses that go beyond credential protection to detect the behavioral signatures of active malware operating on the device.

Source

  • SecurityWeek: Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
#Malware#Banking Trojan#Android#Latin America#Fraud

Related Articles

ToxicPanda 2.0 Android Banking Trojan Abuses VPN Permissions to Neutralize Google Play Protect

ToxicPanda 2.0 targets 349 financial apps across 16 countries, using VPN hijacking and ADB abuse to bypass Android security.

4 min read

Hackers Infect Android Car Head Units with Proxy Botnet Malware

A supply-chain attack trojanizes a legitimate Android car head unit update app to quietly enlist vehicles in a proxy botnet or commit ad fraud.

4 min read

Inside the Underground Business of BTMOB RAT

Flare researchers analyzed thousands of underground posts to reveal how the BTMOB Android RAT evolved from a single MaaS product into a fragmented ecosystem of resellers, source-code vendors, and independent fork operators.

6 min read
Back to all News