{"id":17995,"date":"2026-08-22T09:57:00","date_gmt":"2026-08-22T09:57:00","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17995"},"modified":"2026-08-22T09:57:00","modified_gmt":"2026-08-22T09:57:00","slug":"banking-trojans-manic-grandoreiro-toxicpanda-2-0-within-the-highlight","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17995","title":{"rendered":"Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 within the Highlight"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\"><strong>Cybersecurity corporations this week shared details about new and up to date banking trojans focusing on customers worldwide.<\/strong><\/p>\n<p class=\"wp-block-paragraph\">A lot of these malware can allow their operators to phish credentials, steal delicate consumer information, and remotely management compromised units.\u00a0<\/p>\n<h2 id=\"h-manic\" class=\"wp-block-heading\">Manic<\/h2>\n<p class=\"wp-block-paragraph\">ThreatFabric has detailed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.threatfabric.com\/blogs\/manic-blend-between-banking-malware-and-spyware\">Manic<\/a>, described as an Android malware that mixes banking trojan and adware capabilities.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The malware has primarily been used in opposition to Ukraine, together with banks, authorities companies, and messaging purposes. Nonetheless, it has additionally been noticed focusing on Russian and European monetary establishments, international cryptocurrency and fintech companies, and military-focused messaging apps.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Distributed through malicious web sites and droppers, the malware permits attackers to log keystrokes, show phishing screens, and remotely management the compromised cellphone for banking and cryptocurrency fraud.<\/p>\n<p class=\"wp-block-paragraph\">As well as, Manic consists of adware capabilities reminiscent of notification monitoring, location monitoring, file harvesting, and distant machine surveillance.<\/p>\n<div class=\"zox-post-ad-wrap\"><span class=\"zox-ad-label\">Commercial. Scroll to proceed studying.<\/span><\/div>\n<p class=\"wp-block-paragraph\">\u201cA very distinctive functionality is its offline mesh relay, which permits collected information to maneuver by close by contaminated units over Wi-Fi Direct or Bluetooth when direct C2 entry is unavailable,\u201d ThreatFabric famous.<\/p>\n<h2 id=\"h-grandoreiro\" class=\"wp-block-heading\">Grandoreiro<\/h2>\n<p class=\"wp-block-paragraph\">The Acronis Menace Analysis Unit warned that the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.acronis.com\/en\/tru\/posts\/grandoreiro-goes-north-from-brazil-to-mexico-with-a-new-dll-sideloading-campaign\/\">Grandoreiro<\/a> banking trojan stays energetic, persevering with to concentrate on customers in Latin America.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Grandoreiro was additionally seen <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/fresh-grandoreiro-banking-trojan-campaigns-target-latin-america-europe\/\">focusing on Europe<\/a> final yr, and it continues to focus on Europe alongside North America. Nonetheless, a current marketing campaign monitored by Acronis noticed the majority of assaults geared toward Mexico.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The Home windows malware, of Brazilian origin, has been round for a decade, and it has continued to enhance regardless of regulation enforcement\u2019s makes an attempt to disrupt it.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Latest samples abuse the legit Duplicate Recordsdata Finder (DFF) utility to execute malicious code by DLL sideloading. This enables the malware to mix with common software program exercise and keep away from detection.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe preliminary pattern incorporates in depth anti-analysis performance, together with sandbox detection, digital machine artifact checks, course of blacklisting and surroundings profiling designed to evade automated evaluation methods,\u201d Acronis defined. \u201cThese checks are carried out earlier than any try and contact the command-and-control (C2) infrastructure, suggesting that avoiding evaluation is a excessive precedence for the operators.\u201d<\/p>\n<h2 id=\"h-toxicpanda-2-0\" class=\"wp-block-heading\">ToxicPanda 2.0<\/h2>\n<p class=\"wp-block-paragraph\">Cell safety agency Zimperium has issued a warning over an up to date variant of ToxicPanda, which is thought to primarily <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/android-banking-trojan-toxicpanda-targets-europe\/\">goal Europe<\/a>.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The Android banking trojan\u2019s newest model introduces vital adjustments, together with help for 167 distant instructions and a goal listing of almost 350 monetary purposes; earlier variations focused solely 16 apps.\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/zimperium.com\/blog\/the-toxicpanda-never-sleeps-toxicpanda-2.0-prepares-its-next-strike-on-mobile\">ToxicPanda 2.0<\/a> is designed to focus on monetary establishments throughout 16 international locations, together with Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe malware additionally introduces an automatic click-based mechanism to abuse Android Wi-fi Debugging (ADB), enabling privilege escalation and shell-level entry on compromised units,\u201d Zimperium defined.<\/p>\n<p class=\"wp-block-paragraph\">It added, \u201cThe up to date marketing campaign additionally reveals a shift in distribution strategies, with ToxicPanda 2.0 samples being delivered by Amazon AWS-hosted buckets, indicating the attackers are leveraging cloud infrastructure for malware supply.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/rust-supply-chain-attack-linked-to-north-korean-hackers\/\">Rust Provide Chain Assault Linked to North Korean Hackers<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/amnesiastealer-macos-malware-steals-data-controls-browser-sessions\/\">AmnesiaStealer macOS Malware Steals Information, Controls Browser Periods<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/stealthy-city-forum-attacks-target-salesforce-and-servicenow-with-custom-toolset\/\">Stealthy \u2018Metropolis-Discussion board\u2019 Assaults Goal Salesforce and ServiceNow With Customized Toolset<\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity corporations this week shared details about new and up to date banking trojans focusing on customers worldwide. A lot of these malware can allow their operators to phish credentials, steal delicate consumer information, and remotely management compromised units.\u00a0 Manic ThreatFabric has detailed Manic, described as an Android malware that mixes banking trojan and adware [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17997,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[4365,9239,10267,3616,10268,10266],"class_list":["post-17995","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-banking","tag-grandoreiro","tag-manic","tag-spotlight","tag-toxicpanda","tag-trojans"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17995","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17995"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17995\/revisions"}],"predecessor-version":[{"id":17996,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17995\/revisions\/17996"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17997"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-22 11:53:51 UTC -->