Key Takeaways
- Manic is an Android malware that blends banking‑trojan and spyware functions, using an offline mesh relay to exfiltrate data via Wi‑Direct or Bluetooth when C2 servers are unreachable.
- Grandoreiro, a decade‑old Brazilian banking trojan, continues to evolve, now abusing the legitimate Duplicate Files Finder (DFF) tool via DLL sideloading and employing extensive anti‑analysis checks before contacting its command‑and‑control infrastructure.
- ToxicPanda 2.0 expands its reach dramatically, supporting 167 remote commands, targeting nearly 350 financial apps across 16 countries, and leveraging Amazon AWS‑hosted buckets for distribution, while adding an automated ADB‑based click mechanism for privilege escalation.
- All three threats illustrate a trend toward multi‑function malware, stealthy distribution (cloud services, legitimate software abuse), and advanced evasion techniques that challenge traditional detection methods.
Overview of Recent Banking‑Trojan Activity
Cybersecurity firms have reported a wave of new and updated banking trojans that threaten users worldwide. These malware families are designed to harvest credentials, siphon sensitive data, and grant attackers remote control over compromised devices, enabling fraud against banks, cryptocurrency platforms, and other financial services. The three most notable threats highlighted this week are Manic, Grandoreiro, and ToxicPanda 2.0, each exhibiting distinct capabilities, regional focuses, and evasion tactics that reflect the evolving sophistication of cyber‑criminal operations.
Manic: Android Banking Trojan with Spyware and Offline Mesh Relay
ThreatFabric detailed Manic, an Android malware that combines traditional banking‑trojan features with robust spyware functionalities. The malware has been primarily observed targeting Ukrainian entities—including banks, government services, and messaging apps—but also appears in attacks against Russian and European financial institutions, global cryptocurrency platforms, fintech services, and military‑oriented messaging applications. Distribution occurs through malicious websites and droppers that install the payload on victims’ devices. Once active, Manic can log keystrokes, overlay phishing screens to steal login credentials, and remotely control the phone for illicit banking and cryptocurrency transactions. Its spyware suite includes notification monitoring, GPS‑based location tracking, file harvesting, and live device surveillance. A standout feature is its offline mesh relay mechanism, which allows collected data to hop between nearby infected devices using Wi‑Direct or Bluetooth when direct command‑and‑control (C2) communication is unavailable, thereby increasing resilience against network‑based takedowns.
Grandoreiro: Persistent Brazilian Banking Trojan Leveraging Legitimate Software
The Acronis Threat Research Unit warned that Grandoreiro, a banking trojan of Brazilian origin that has been active for roughly ten years, remains a potent threat, particularly in Latin America. While historically focused on that region, Grandoreiro has also been seen targeting European and North American users, with a recent Acronis‑monitored campaign concentrating heavily on Mexico. The Windows‑based malware continues to improve despite law‑enforcement disruption attempts. Recent samples abuse the legitimate Duplicate Files Finder (DFF) application through DLL sideloading, enabling the malicious code to execute under the guise of a trusted program and evade signature‑based detection. Before any C2 contact, Grandoreiro performs extensive anti‑analysis checks: sandbox detection, virtual‑machine artifact identification, process blacklisting, and environmental profiling. These measures are designed to thwart automated analysis systems, indicating that the operators prioritize stealth over immediate communication with their infrastructure.
ToxicPanda 2.0: Expanded Command Set, Cloud Distribution, and ADB Exploit
Mobile security firm Zimperium issued an alert regarding an updated variant of the Android banking trojan ToxicPanda, dubbed ToxicPanda 2.0. This version dramatically broadens the trojan’s capabilities, introducing support for 167 remote commands and a target list encompassing nearly 350 financial applications—up from the previous limit of around 16 apps. ToxicPanda 2.0 aims at institutions across 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama. Beyond credential theft, the malware now incorporates an automated click‑based mechanism that abuses Android Wireless Debugging (ADB) to achieve privilege escalation and obtain shell‑level access on compromised devices, facilitating deeper control and data exfiltration. Distribution tactics have also shifted; Zimperium observed ToxicPanda 2.0 samples being hosted in Amazon AWS S3 buckets, highlighting the attackers’ use of reputable cloud infrastructure to deliver malware while bypassing traditional reputation‑based filters. This combination of expanded functionality, privilege‑escalation tricks, and cloud‑based delivery underscores a move toward more versatile and harder‑to‑detect mobile threats.
Implications and Defensive Recommendations
The emergence of Manic, Grandoreiro, and ToxicPanda 2.0 illustrates several overarching trends in banking‑trojan evolution. First, malware is increasingly multifunctional, blending traditional financial theft with espionage‑style surveillance to maximize the value of each infection. Second, attackers are leveraging legitimate software and cloud services—such as DFF and AWS—to blend malicious activity with benign traffic, complicating detection for both signature‑based and behavioral security tools. Third, advanced evasion techniques, including offline mesh relays, extensive anti‑analysis checks, and abuse of debugging interfaces, are becoming commonplace, necessitating deeper scrutiny of endpoint behavior and network anomalies.
Organizations and individuals should adopt a layered defense strategy: keep operating systems and applications patched, enforce application‑whitelisting or strict installation policies, monitor for unusual use of ADB or wireless‑debugging features, and employ threat‑intelligence feeds that flag known malicious domains, IP ranges, and cloud‑storage buckets. Additionally, user awareness training remains critical, as many of these threats still rely on social engineering or malicious websites to gain initial access. By understanding the specific tactics, techniques, and procedures (TTPs) of threats like Manic, Grandoreiro, and ToxicPanda 2.0, defenders can better prioritize controls and reduce the risk of credential theft, financial fraud, and data loss.

