Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
Manic is a new Android banking trojan and spyware hybrid primarily targeting Ukraine, with capabilities including offline mesh relay for data exfiltration via Wi-Fi Direct or Bluetooth when C2 access is unavailable Grandoreiro, a decade-old Brazilian banking trojan, remains active with new evasion techniques including DLL sideloading through legitimate Duplicate Files Finder (DFF) software and extensive anti-analysis checks before C2 contact ToxicPanda 2.0 represents a major escalation with supp
Analysis
TL;DR
- Manic is a new Android banking trojan and spyware hybrid primarily targeting Ukraine, with capabilities including offline mesh relay for data exfiltration via Wi-Fi Direct or Bluetooth when C2 access is unavailable
- Grandoreiro, a decade-old Brazilian banking trojan, remains active with new evasion techniques including DLL sideloading through legitimate Duplicate Files Finder (DFF) software and extensive anti-analysis checks before C2 contact
- ToxicPanda 2.0 represents a major escalation with support for 167 remote commands, nearly 350 targeted financial apps (up from 16), automated Android ADB abuse for privilege escalation, and cloud-based distribution via AWS-hosted buckets
- All three threats demonstrate a trend toward sophisticated evasion, cloud infrastructure abuse, and expanding target scope across financial, cryptocurrency, and government sectors
Why It Matters
The rapid evolution and increasing sophistication of these banking trojans pose direct risks to financial institutions, individual users, and enterprise security teams worldwide. The shift toward cloud-based distribution and offline data relay mechanisms indicates attackers are adapting to improve resilience against takedowns and network monitoring. Security practitioners must update detection rules and endpoint protection strategies to address these emerging techniques.
Technical Details
- Manic: Android malware combining banking trojan and spyware; features keystroke logging, phishing screen injection, notification monitoring, location tracking, file harvesting, and a distinctive offline mesh relay using Wi-Fi Direct/Bluetooth for peer-to-peer data forwarding when direct C2 is unavailable; distributed via malicious websites and droppers
- Grandoreiro: Windows-based banking trojan of Brazilian origin; employs DLL sideloading by abusing the legitimate Duplicate Files Finder (DFF) application; implements pre-C2 anti-analysis checks including sandbox detection, VM artifact identification, process blacklisting, and environment profiling to evade automated analysis systems
- ToxicPanda 2.0: Android banking trojan with 167 remote commands and ~350 targeted financial applications across 16 countries; introduces automated click-based Android Wireless Debugging (ADB) abuse for privilege escalation and shell-level access; leverages Amazon AWS-hosted buckets for malware distribution, marking a shift to cloud infrastructure for delivery
Industry Insight
- Financial institutions and fintech companies should prioritize mobile security monitoring, especially for Android devices, and implement detection for ADB abuse patterns and unusual wireless debugging activity
- Organizations should reassess supply chain and software integrity controls, as the Grandoreiro DLL sideloading technique demonstrates how legitimate tools can be weaponized to bypass security defenses
- The adoption of cloud infrastructure (AWS buckets) for malware distribution by ToxicPanda 2.0 signals a broader trend of attackers leveraging legitimate cloud services for operational resilience, prompting the need for enhanced cloud security monitoring and threat intelligence sharing across the cybersecurity community
Disclaimer: The above content is generated by AI and is for reference only.