
ACCORDING to a report published by SecurityWeek, three banking trojans, Grandoreiro, Manic and ToxicPanda 2.0, are actively targeting financial institutions and customers across the globe. The campaigns have been observed in Europe, Latin America and parts of Asia, prompting concern among banks and incident response teams.
Manic is an Android trojan that combines banking fraud with spyware functions. It can log keystrokes, harvest contact lists and steal data from cryptocurrency wallets and military‑related apps, then use offline mesh relays to exfiltrate information when a direct connection is unavailable. Researchers note that its primary focus has been Ukrainian institutions, but infections have also been seen in Russian and European banks.
Grandoreiro, a Windows banking trojan first seen in 2016, has resurfaced with a new campaign that relies on DLL sideloading through the legitimate Duplicate Files Finder application. The malware incorporates anti‑analysis tricks to frustrate sandboxing and detection tools, allowing it to operate stealthily. Acronis reports that the current wave targets users in Mexico and Europe and has been linked to more than 1,700 banks in 45 countries worldwide.
ToxicPanda 2.0 represents the latest iteration of an Android trojan aimed at financial applications across sixteen countries. It employs overlay screens to capture login credentials and can intercept SMS messages to bypass two‑factor authentication. Although fewer technical details have been made public, analysts say the malware shares code reuse with earlier variants and continues to evolve.
None of the three families have been tied to a specific threat actor group, and no CVEs have been assigned to the recent activity. Despite a law enforcement operation that disrupted parts of the Grandoreiro infrastructure earlier this year, the operators have revived their campaigns using updated delivery mechanisms such as weaponised ZIP files containing benign‑looking documents. The use of mesh relays by Manic and DLL sideloading by Grandoreiro illustrates a broader trend toward living‑off‑the‑land techniques designed to evade traditional defences.
Defenders should monitor endpoint logs for unexpected DLL loads, especially from trusted utilities, and enforce application‑control policies that block unsigned or unknown libraries. Keeping antivirus and endpoint detection platforms up to date helps catch known signatures, while behaviour‑based rules can flag the unusual mesh‑relay traffic used by Manic for data exfiltration. Network sensors ought to watch for peer‑to‑peer connections that deviate from normal browsing patterns, particularly those using non‑standard ports.
User awareness remains critical; training staff to recognise phishing emails and suspicious attachments reduces the chance of initial infection. Enforcing multi‑factor authentication on banking applications adds a layer of protection even if credentials are captured. Finally, organisations should enrich their threat‑intelligence feeds with the indicators shared in the Acronis and SecurityWeek reports and hunt regularly for signs of these trojans.