Banking Trojans Manic, Grandoreiro, and ToxicPanda 2.0: Rising Cybersecurity Threats
Cybersecurity firms have reported recent developments involving multiple banking trojans targeting global users.
Manic
ThreatFabric has identified Manic, an Android malware combining banking trojan and spyware functionalities. The malware has primarily targeted Ukraine, including financial institutions, government services, and messaging platforms, while also extending its reach to Russian and European financial entities, global cryptocurrency services, and military-focused communication apps.
Distribution Methods
It is distributed through malicious websites and droppers, enabling keystroke logging, phishing screens, and remote device control for financial and crypto fraud.
Spyware Features
Additional spyware features include notification monitoring, location tracking, file collection, and remote surveillance. A notable feature is its offline mesh relay capability, allowing data transmission between infected devices via Wi-Fi Direct or Bluetooth when direct C2 access is unavailable.
Grandoreiro
The Acronis Threat Research Unit has highlighted the ongoing activity of Grandoreiro, a Windows-based banking trojan originating from Brazil. Despite law enforcement efforts to disrupt its operations, the malware remains active, with recent campaigns focusing on Latin America, particularly Mexico.
Evolving Techniques
Grandoreiro has evolved over the past decade, leveraging the legitimate Duplicate Files Finder (DFF) application to execute malicious code through DLL sideloading. This technique allows the malware to mimic normal software behavior, evading detection.
ToxicPanda 2.0
Zimperium has issued warnings about an updated variant of ToxicPanda, an Android banking trojan primarily targeting Europe. The latest iteration, ToxicPanda 2.0, introduces expanded capabilities, including support for 167 remote commands and a target list of nearly 350 financial applications—up from 16 in earlier versions.
Expanded Capabilities
The malware focuses on financial institutions across 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama. A key enhancement involves an automated click-based mechanism exploiting Android Wireless Debugging (ADB) to achieve privilege escalation and shell-level access on compromised devices.
Distribution Shifts
Distribution methods have shifted to Amazon AWS-hosted buckets, indicating the use of cloud infrastructure for malware delivery.
Other Reported Threats
Other reported threats include active exploitation campaigns targeting Zimbra servers, AI-driven attacks on Siemens PLCs in critical U.S. sectors, and ransomware groups releasing victim lists. Additionally, vulnerabilities in Microsoft Entra ID and supply chain compromises linked to North Korean hackers have been documented.
Conclusion
The cybersecurity landscape continues to evolve, with threat actors refining techniques to bypass defenses and expand their attack surfaces. Organizations are advised to implement robust endpoint protection, monitor for anomalous network activity, and stay informed about emerging threats.
