HackMyIP
← Back to News
2026-08-22 SecurityWeek

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Target Global Users

MalwareThreat IntelPhishing

Three major banking trojan families—Manic, Grandoreiro, and an updated ToxicPanda variant—are actively targeting financial institutions and end users across multiple continents, according to fresh intelligence from ThreatFabric, Acronis, and Zimperium. These malware families enable credential phishing, sensitive data theft, and remote device control, putting both consumer banking and enterprise fintech environments at risk. Researchers warn that the operators behind each strain continue to refine evasion techniques while expanding their geographic and application reach.

ThreatFabric has profiled Manic, an Android strain blending banking trojan functionality with full spyware capabilities. Primarily aimed at Ukrainian banks, government services, and military messaging apps, Manic has also been observed hitting Russian and European financial institutions as well as global cryptocurrency and fintech platforms. Distributed via malicious websites and dropper apps, it logs keystrokes, overlays phishing screens, and provides remote control for banking and crypto fraud. Its most notable feature is an offline mesh relay that exfiltrates stolen data through nearby infected devices over Wi-Fi Direct or Bluetooth when direct command-and-control access is blocked. Users worried about mobile credential exposure can run an email breach checker to confirm whether their accounts have already appeared in leaked datasets.

Grandoreiro, a Brazilian-origin Windows trojan active for roughly a decade, continues targeting users in Latin America—with Mexico absorbing the bulk of a recent campaign observed by the Acronis Threat Research Unit—while simultaneously pursuing victims in Europe and North America. The latest samples abuse the legitimate Duplicate Files Finder utility to execute malicious payloads through DLL sideloading, helping the malware blend into normal software activity. Before contacting its C2 infrastructure, Grandoreiro runs sandbox checks, virtual machine artifact detection, process blacklisting, and environment profiling to thwart automated analysis.

ToxicPanda 2.0, documented by Zimperium, represents a significant overhaul of the Android banking trojan previously focused on Europe. The updated variant now supports 167 remote commands and a target list of nearly 350 financial applications, up from just 16 in prior builds, and is aimed at institutions across 16 countries including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama. Users who suspect exposure to credential-stealing malware should immediately test their credentials with a password checker and rotate any banking passwords tied to compromised devices, while mobile users concerned about spyware monitoring can perform a full privacy checkup to identify overly permissive app permissions.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →