Tre trojan bancari rilanciano la minaccia contro Android e Windows
Malware

Illustrative image generated with AI

Three Banking Trojans Renew the Threat to Android and Windows

Three new banking trojans—Manic, Grandoreiro, and ToxicPanda 2.0—threaten Android and Windows users with sophisticated fraud techniques.

Text generated by artificial intelligence, published without human review. AI transparency

Reports gathered on August 22, 2026, describe three new or updated malware families: Manic, Grandoreiro, and ToxicPanda 2.0. They target Android smartphones and Windows computers using different techniques, but share the same goals: stealing credentials, controlling devices, and enabling banking or cryptocurrency-related fraud.

Manic Turns Android Smartphones into Surveillance Nodes

ThreatFabric analyzed Manic, an Android malware strain combining banking Trojan and spyware capabilities. Its primary area of activity is Ukraine, where it has targeted banks, government services, and messaging applications.

The threat has also been observed targeting Russian and European financial institutions, global cryptocurrency and fintech platforms, and messaging applications used in military environments.

Manic may arrive through malicious websites or droppers—components designed to install malware on a device. Once executed, it can log user input, display phishing screens, and enable remote control of the smartphone.

Its capabilities extend beyond banking operations. The Trojan can monitor notifications, track the device’s location, collect files, and remotely surveil the phone. Notifications may also expose one-time codes, authentication messages, or other information useful for completing a fraud.

Its most unusual feature is an offline mesh relay system. If an infected smartphone cannot directly reach the command-and-control server, it can transfer data through other compromised devices nearby. The connection may use Wi-Fi Direct or Bluetooth.

As a result, the lack of a direct connection to the criminal infrastructure does not necessarily stop data exfiltration. Infected devices can act as intermediaries, creating a local network among themselves.

Grandoreiro Abuses Legitimate Windows Software

Grandoreiro remains primarily active in Latin America, with Mexico at the center of the latest campaign monitored by Acronis. The Trojan originated in Brazil and has been active for roughly a decade, while continuing to target victims in Europe and North America.

Unlike Manic and ToxicPanda, Grandoreiro operates on Windows. Recent samples abuse Duplicate Files Finder, a legitimate application, to load malicious code through DLL sideloading.

The technique exploits how a program searches for and loads its libraries. If a tampered DLL is placed in the expected location, the legitimate application may also execute the malicious component. Using genuine software makes the activity harder to distinguish from normal processes running on the system.

The initial sample also contains extensive anti-analysis mechanisms. Grandoreiro checks for sandboxes, looks for virtual machine artifacts, analyzes running processes, and profiles the operating environment.

It also includes process blacklists and checks designed to evade automated analysis systems. These checks take place before the malware attempts to contact its command-and-control infrastructure: it first tries to determine whether it is running on a real computer or in an environment used by researchers.

This behavior complicates the work of defensive teams. A sample may remain inactive during automated analysis and activate only when it detects conditions consistent with a workstation used in everyday operations.

ToxicPanda 2.0 Dramatically Expands Its Financial Targets

Zimperium identified ToxicPanda 2.0, an updated variant of the Android banking Trojan known for its activity primarily in Europe.

The most significant change concerns its attack surface. The new version contains a list of nearly 350 financial applications, whereas previous versions targeted only 16. The malware is designed to attack financial institutions across 16 countries.

The countries listed include Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama. Its scope therefore covers highly diverse markets and is not limited to a single national banking system.

ToxicPanda 2.0 supports 167 remote commands. Operators can issue a wide range of instructions to compromised devices, adapting the Trojan’s behavior to the smartphone model, the financial application in use, or the stage of the fraud.

The variant also introduces an automated click-based mechanism to abuse Android Wireless Debugging, also known as ADB. This feature may enable privilege escalation and shell access to the device.

Shell access gives attackers broader control than simply displaying a fake overlay. Depending on the privileges obtained, it can allow them to execute commands, query the system, and interact with components normally inaccessible to standard applications.

Its distribution method has also changed. Observed samples are hosted in Amazon AWS buckets, using legitimate—or broadly available—cloud infrastructure to deliver the malware to victims.

Three Different Paths to Fraud

The three families demonstrate complementary approaches.

Manic combines data theft, surveillance, remote control, and communication between infected devices. Its impact may extend beyond the bank account to files, location data, notifications, and conversations stored on the smartphone.

Grandoreiro, by contrast, focuses on compromising Windows systems through legitimate software and DLL sideloading. Its anti-sandbox and anti-virtualization defenses are designed to reduce the likelihood of detection during analysis.

ToxicPanda 2.0 expands the number of financial applications it can target and adds a far more sophisticated remote-control system. Its abuse of ADB also increases the risk of low-level access to the device.

Potential victims include Android users, employees working on Windows workstations, banks, fintech services, cryptocurrency platforms, government agencies, and messaging applications. Consequences may include credential theft, notification interception, file exfiltration, location tracking, and fraudulent transactions.

What to Monitor—and Which Details Are Still Missing

No CVE identifiers, affected software versions, patches, indicators of compromise, or specific removal procedures have been disclosed. It is also unknown whether these threats have been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.

Operationally, administrators should watch for installations from unofficial websites and Android droppers associated with Manic. They should also investigate unusual requests for remote control and abnormal access to notifications, location data, files, and accessibility features.

For Grandoreiro, unexpected execution of Duplicate Files Finder, abnormal DLL loading, and anti-analysis checks should be correlated with process and network telemetry. For ToxicPanda 2.0, particular attention should be paid to connections to suspicious AWS buckets, unexpected activation of Wireless Debugging, and unusual use of ADB or the shell.

Users should install applications only from trusted sources, keep wireless debugging disabled when it is not needed, and confirm any unexpected transaction with their bank. For organizations, centralized monitoring of mobile devices, Windows processes, and access to financial applications remains essential, as no dedicated fixes are currently available for these three malware families.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsbanking trojansAndroid malwareWindows malwareManicGrandoreiroToxicPanda 2.0credential theftcybersecurity threats
Back to home