Security researchers published findings this week on three separate banking trojan operations, underscoring how both Android and Windows financial malware continue to add capabilities and evade detection.
Manic targets Ukraine, expands globally
ThreatFabric detailed a new Android threat called Manic that blends banking trojan and spyware functions. The malware has primarily targeted Ukrainian banks, government services, and messaging apps, but has also been spotted against Russian and European financial institutions, global cryptocurrency and fintech platforms, and military-focused messaging applications.
Manic spreads through malicious websites and droppers. Once installed, it can log keystrokes, display phishing overlays, and give attackers remote control of a device to commit banking and cryptocurrency fraud. It also carries spyware features including notification monitoring, location tracking, file harvesting, and device surveillance. One notable feature is an offline mesh relay that lets stolen data hop between nearby infected devices over Wi-Fi Direct or Bluetooth when a direct connection to command-and-control infrastructure is unavailable.
Grandoreiro remains active a decade on
Acronis’ Threat Research Unit reported that Grandoreiro, a Brazilian-origin Windows banking trojan active for roughly ten years, is still evolving despite repeated law enforcement disruption attempts. While the malware continues to target Latin America, Europe, and North America, a recent campaign monitored by Acronis showed the bulk of attacks concentrated on Mexico.
Recent samples abuse the legitimate Duplicate Files Finder application through DLL sideloading, letting the malicious code blend in with normal software activity. Acronis noted that the initial sample includes extensive anti-analysis functionality, such as sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling, all performed before any contact with command-and-control infrastructure, suggesting operators prioritize evading analysis.
ToxicPanda 2.0 massively expands its target list
Zimperium warned of an updated version of ToxicPanda, an Android banking trojan mainly known for targeting Europe. The new variant supports 167 remote commands and targets nearly 350 financial applications, up from just 16 in earlier versions. ToxicPanda 2.0 focuses on financial institutions across 16 countries including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama.
The malware introduces an automated click-based mechanism that abuses Android Wireless Debugging to escalate privileges and gain shell-level access on compromised devices. Zimperium also observed a shift in distribution, with ToxicPanda 2.0 samples delivered through Amazon AWS-hosted buckets, indicating attackers are leveraging cloud infrastructure to host and distribute the malware.
