Skip to content
feed: live
>_0dayNews
mobile
● Breaking

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active

Three banking trojans are active: spyware-equipped Manic, persistent Grandoreiro across Latin America and Europe, and an expanded ToxicPanda 2.0.

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Active
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·2 min read

Three distinct banking trojan campaigns are running simultaneously. SecurityWeek, August 22. Full operational picture on each is still developing.

Manic

New entry. Confirmed: spyware module bundled alongside banking credential-theft capability. Standard banking trojans go after account access. Manic’s spyware component means the operators want persistent visibility into the device — broader intelligence collection beyond a single account drain. Attribution: unconfirmed. Geographic targeting scope: not yet published. Confidence on spyware claim: per SecurityWeek reporting. Treat campaign scope details as unconfirmed until corroborated by additional research.

Grandoreiro

Persistent. Confirmed active in Latin America and Europe. Grandoreiro has been targeting banking customers since at least 2017. Brazilian Federal Police arrested several operators in January 2024 — infrastructure disruption was real and temporary. Campaigns resumed. The current wave extends Grandoreiro’s traditional Latin American target base into European markets. Spanish and Portuguese speakers are the primary demographic. Confidence: high on campaign continuity; geographic spread confirmed in current reporting cycle.

ToxicPanda 2.0

Expanded. Cleafy researchers first documented ToxicPanda in late 2024 targeting European bank customers — Italy, Portugal, Spain, the UK, France, and Peru. Attack method: Android accessibility service abuse to run overlay attacks against banking apps and intercept one-time passwords before the legitimate app sees them. The 2.0 iteration is active and operationally larger than the original. Capability delta over the initial version is still being mapped. Confidence: confirmed active; full scope under assessment.

Assessment

Three separate operations with overlapping target demographics. No confirmed infrastructure sharing or coordination between them — treat as independent threat actor groups until evidence says otherwise. The timing is coincidence until proven otherwise.

The pattern Grandoreiro and ToxicPanda both demonstrate: banking trojans do not stop when hit by law enforcement or initial research exposure. They reorganize. ToxicPanda added a version number. Grandoreiro rebuilt after arrests. Manic is either new or newly observed — unknown which. [Analysis: elevated confidence that mobile banking fraud operations are in an active expansion phase, not winding down.]

Mitigation

Android users with mobile banking apps:

  • Audit accessibility service permissions now. Any app with accessibility access that you did not explicitly grant is a red flag. Revoke it.
  • An OTP arriving without a login action you initiated is a signal of active fraud. Do not enter the code. Call your bank directly.
  • Install banking apps only from your bank’s official distribution channel or verified app store listing.

Organizations with BYOD policies allowing financial system access should enforce MDM controls with visibility into accessibility service grants.


Related: Android Malware Relays NFC Cards, Takes Out Loans · Flying Eagle Android RAT Source Code Leaks to Telegram · Car Infotainment Units Hijacked via Supply-Chain Attack

Found this useful? Share it.