Overview
Security researchers have brought three active banking trojans back into focus this week: Manic, a newly characterized spyware-equipped banking malware; Grandoreiro, a long-running campaign persisting across Latin America and Europe despite law enforcement disruption; and ToxicPanda 2.0, an expanded version of the Android banking trojan that has broadened its targeting to additional countries and banking institutions.
Together they represent the ongoing industrialization of financial fraud malware — each with distinct technical profiles and geographic focuses, but sharing a common goal: stealing banking credentials and authorizing fraudulent transactions.
Manic: Spyware-Equipped Banking Malware
Manic is a newly detailed banking trojan notable for integrating spyware capabilities alongside its core credential-theft functions. Unlike traditional banking malware that focuses narrowly on overlay attacks or keylogging, Manic's spyware component enables:
- Continuous screen capture and exfiltration — providing operators with real-time visibility into victim activity
- Contact list and SMS harvesting — useful for SIM-swap support, social engineering of victims' contacts, or bypassing SMS-based two-factor authentication
- Microphone and camera access — enabling audio/video surveillance in tandem with financial fraud
The combination of espionage and fraud capabilities in a single implant suggests a more sophisticated threat actor with interests beyond a quick account drain — potentially enabling sustained access to high-value targets.
Grandoreiro: Persistent and Resilient
Grandoreiro is one of the most well-documented banking trojans in the wild, originally emerging from Brazil and expanding aggressively through Latin America and Europe. Despite a significant law enforcement operation in early 2024 that led to arrests of key operators, the malware has proven remarkably resilient — new infrastructure and updated variants continue to surface.
Key characteristics of current Grandoreiro campaigns:
- Phishing-led distribution — spam campaigns impersonating tax authorities, utilities, and financial institutions deliver the initial loader
- DGA (Domain Generation Algorithm) — Grandoreiro uses a DGA to generate C2 domains, making infrastructure blocking significantly harder for defenders
- Backdoor functionality — beyond banking fraud, recent variants include remote desktop capabilities and file exfiltration
- Geographic expansion — campaigns have been observed targeting Spain, Portugal, Argentina, Mexico, and several other countries, reflecting the operators' continued investment in the platform
The persistence of Grandoreiro illustrates how difficult it is to permanently disrupt malware ecosystems when the underlying code and criminal network remain intact.
ToxicPanda 2.0: Broader Targeting, Deeper Capabilities
ToxicPanda debuted in late 2024 as an Android banking trojan targeting primarily Italian and Portuguese-speaking markets. The 2.0 variant analyzed in current research represents a significant evolution:
- Expanded bank targeting — the new version's target list has grown substantially, now covering institutions in additional European and Asian markets
- Improved ATS (Automated Transfer System) — ToxicPanda 2.0 has refined its on-device fraud engine, allowing it to automate fund transfers without requiring real-time operator interaction
- Enhanced evasion — updated code obfuscation and anti-analysis techniques complicate detection by mobile security solutions
- OTP interception — the malware continues to excel at intercepting one-time passwords delivered via SMS or notification, bypassing standard 2FA
The ATS capability is particularly dangerous: rather than simply stealing credentials for later use, ToxicPanda can complete the full fraud cycle — authenticating, navigating the banking app, and transferring funds — automatically, at scale, in the background while the victim's device appears idle.
Geographic Focus and Target Overlap
| Trojan | Primary Regions | Delivery | Key Capability |
|---|---|---|---|
| Manic | TBD / emerging | Likely phishing/APK | Spyware + credential theft |
| Grandoreiro | Latin America, Europe (ES, PT) | Phishing email | DGA C2, RDP backdoor |
| ToxicPanda 2.0 | Europe, Asia (expanding) | Malicious APK | Automated on-device fraud |
Defensive Recommendations
For individual users:
- Only install banking apps from official app stores (Google Play, App Store)
- Enable Google Play Protect and do not sideload APKs from unknown sources
- Be suspicious of unsolicited emails or SMS messages impersonating banks, tax agencies, or utilities — do not click embedded links
- Use a hardware security key or authenticator app for 2FA where available, as these are significantly harder for trojans to bypass than SMS OTPs
For financial institutions:
- Deploy behavioral biometrics and anomaly detection on mobile banking sessions — unusual navigation patterns or transaction velocity can surface ATS activity
- Implement transaction risk scoring that factors in device signals (rooting, overlay permissions, unusual accessibility service usage)
- Consider requiring step-up authentication for high-value transactions, with out-of-band confirmation channels
For security teams:
- Monitor for indicators of compromise (IoCs) associated with all three families — threat intel feeds from sources tracking Latin American and Android malware are particularly useful here
- Review mobile app store reviews and abuse reports for signs of overlay or impersonation attacks targeting your institution
Key Takeaway
The simultaneous spotlight on Manic, Grandoreiro, and ToxicPanda 2.0 underscores that the banking trojan ecosystem is not contracting — it is evolving. Spyware integration, automated fraud engines, and persistent operator networks make these threats increasingly difficult to disrupt. Financial institutions and their customers need layered defenses that go beyond credential protection to detect the behavioral signatures of active malware operating on the device.