AI Security AI安全 7h ago Updated 2h ago 更新于 2小时前 40

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Manic、Grandoreiro、ToxicPanda 2.0 银行木马成为焦点

Manic is a new Android banking trojan and spyware hybrid primarily targeting Ukraine, with capabilities including offline mesh relay for data exfiltration via Wi-Fi Direct or Bluetooth when C2 access is unavailable Grandoreiro, a decade-old Brazilian banking trojan, remains active with new evasion techniques including DLL sideloading through legitimate Duplicate Files Finder (DFF) software and extensive anti-analysis checks before C2 contact ToxicPanda 2.0 represents a major escalation with supp 本周多家网络安全公司披露了针对全球用户的新型银行木马活动,涵盖Android和Windows平台 Manic恶意软件结合银行木马与间谍软件功能,通过离线网状中继实现数据隐蔽传输 Grandoreiro木马采用DLL侧加载技术伪装合法软件,持续针对拉丁美洲金融用户 ToxicPanda 2.0大幅扩展攻击能力,支持167个远程命令和350个金融应用目标

58
Hot 热度
62
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • Manic is a new Android banking trojan and spyware hybrid primarily targeting Ukraine, with capabilities including offline mesh relay for data exfiltration via Wi-Fi Direct or Bluetooth when C2 access is unavailable
  • Grandoreiro, a decade-old Brazilian banking trojan, remains active with new evasion techniques including DLL sideloading through legitimate Duplicate Files Finder (DFF) software and extensive anti-analysis checks before C2 contact
  • ToxicPanda 2.0 represents a major escalation with support for 167 remote commands, nearly 350 targeted financial apps (up from 16), automated Android ADB abuse for privilege escalation, and cloud-based distribution via AWS-hosted buckets
  • All three threats demonstrate a trend toward sophisticated evasion, cloud infrastructure abuse, and expanding target scope across financial, cryptocurrency, and government sectors

Why It Matters

The rapid evolution and increasing sophistication of these banking trojans pose direct risks to financial institutions, individual users, and enterprise security teams worldwide. The shift toward cloud-based distribution and offline data relay mechanisms indicates attackers are adapting to improve resilience against takedowns and network monitoring. Security practitioners must update detection rules and endpoint protection strategies to address these emerging techniques.

Technical Details

  • Manic: Android malware combining banking trojan and spyware; features keystroke logging, phishing screen injection, notification monitoring, location tracking, file harvesting, and a distinctive offline mesh relay using Wi-Fi Direct/Bluetooth for peer-to-peer data forwarding when direct C2 is unavailable; distributed via malicious websites and droppers
  • Grandoreiro: Windows-based banking trojan of Brazilian origin; employs DLL sideloading by abusing the legitimate Duplicate Files Finder (DFF) application; implements pre-C2 anti-analysis checks including sandbox detection, VM artifact identification, process blacklisting, and environment profiling to evade automated analysis systems
  • ToxicPanda 2.0: Android banking trojan with 167 remote commands and ~350 targeted financial applications across 16 countries; introduces automated click-based Android Wireless Debugging (ADB) abuse for privilege escalation and shell-level access; leverages Amazon AWS-hosted buckets for malware distribution, marking a shift to cloud infrastructure for delivery

Industry Insight

  • Financial institutions and fintech companies should prioritize mobile security monitoring, especially for Android devices, and implement detection for ADB abuse patterns and unusual wireless debugging activity
  • Organizations should reassess supply chain and software integrity controls, as the Grandoreiro DLL sideloading technique demonstrates how legitimate tools can be weaponized to bypass security defenses
  • The adoption of cloud infrastructure (AWS buckets) for malware distribution by ToxicPanda 2.0 signals a broader trend of attackers leveraging legitimate cloud services for operational resilience, prompting the need for enhanced cloud security monitoring and threat intelligence sharing across the cybersecurity community

TL;DR

  • 本周多家网络安全公司披露了针对全球用户的新型银行木马活动,涵盖Android和Windows平台
  • Manic恶意软件结合银行木马与间谍软件功能,通过离线网状中继实现数据隐蔽传输
  • Grandoreiro木马采用DLL侧加载技术伪装合法软件,持续针对拉丁美洲金融用户
  • ToxicPanda 2.0大幅扩展攻击能力,支持167个远程命令和350个金融应用目标

为什么值得看

本文揭示了当前银行恶意软件的技术演进趋势,对金融机构和移动设备用户具有重要警示意义。攻击者正利用云基础设施和合法软件滥用技术提升恶意软件的隐蔽性和传播效率。

技术解析

Manic恶意软件采用离线网状中继机制,通过Wi-Fi Direct或蓝牙在附近感染设备间传输数据,避免直接连接C2服务器,同时具备键盘记录、钓鱼屏幕、通知监控、位置追踪和文件收集等间谍功能。

Grandoreiro利用合法应用程序Duplicate Files Finder(DFF)进行DLL侧加载,在执行恶意代码前进行沙箱检测、虚拟机特征检查、进程黑名单和环境分析等反分析功能,以规避自动化分析系统。

ToxicPanda 2.0引入自动化点击机制滥用Android无线调试(ADB)功能实现权限提升和shell级访问,并通过AWS托管桶分发恶意软件,目标应用从16个扩展至近350个金融应用。

行业启示

攻击者正加速采用云基础设施进行恶意软件分发,金融机构需加强对云端存储和分发渠道的安全监控。恶意软件功能日益融合银行窃取与间谍监控能力,企业需采取更全面的端点安全防护策略。DLL侧加载和合法软件滥用成为主流 evasion 技术,安全产品需提升对这类行为的检测能力。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全