The banking Trojans Manic, Grandoreiro and ToxicPanda 2.0 in the spotlight

The banking Trojans Manic, Grandoreiro and ToxicPanda 2.0 in the spotlight

Cybersecurity companies this week shared information about new and updated banking Trojans targeting users worldwide.

This type of malware can allow its operators to forge login credentials, steal sensitive user data, and remotely control compromised devices.

Manic

ThreatFabric described in detail Manicdescribed as Android malware that combines banking Trojan and spyware features.

The malware was primarily used against Ukraine, including banks, government services and messaging applications. However, it was also seen targeting Russian and European financial institutions, global cryptocurrency and fintech services, and military-focused messaging apps.

The malware is distributed via malicious websites and droppers, allowing attackers to log keystrokes, display phishing screens, and remotely control the compromised phone for banking and cryptocurrency fraud.

Additionally, Manic Spyware includes features such as notification monitoring, location tracking, file collection, and remote device monitoring.

Advertising. Scroll to continue reading.

“A particularly standout feature is offline mesh relay, which allows collected data to be transmitted to nearby infected devices via Wi-Fi Direct or Bluetooth when direct C2 access is not available,” ThreatFabric noted.

Grandoreiro

The Acronis Threat Research Unit warned about this Grandoreiro The banking Trojan remains active and continues to focus on users in Latin America.

Grandoreiro also targeted Europe last year and continues to set his sights on Europe in addition to North America. However, in a recent campaign monitored by Acronis, the majority of attacks targeted Mexico.

The Brazilian-origin Windows malware has been around for a decade and has continued to improve despite law enforcement attempts to stop it.

Current examples abuse the legitimate Duplicate Files Finder (DFF) application to execute malicious code through DLL sideloading. This allows the malware to blend in with regular software activity and avoid detection.

“The first example includes extensive anti-analytics capabilities, including sandbox detection, virtual machine artifact checks, process blacklisting and environmental profiling, designed to bypass automated analytics systems,” Acronis explained. “These checks are performed before any attempt to contact the command and control (C2) infrastructure, indicating that avoiding analysis is a high priority for operators.”

ToxicPanda 2.0

Mobile security company Zimperium has issued a warning about an updated variant of ToxicPanda that is known to primarily target Europe.

The latest version of the Android banking Trojan introduces significant changes including support for 167 remote commands and a target list of nearly 350 financial applications; Previous versions only targeted 16 apps.

ToxicPanda 2.0 is aimed at financial institutions in 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia and Panama.

“The malware also introduces an automated, click-based mechanism to abuse Android Wireless Debugging (ADB), enabling privilege escalation and shell-level access on compromised devices,” Zimperium explained.

It added: “The updated campaign also shows a shift in distribution methods, with ToxicPanda 2.0 samples being delivered via Amazon AWS hosted buckets, suggesting the attackers are leveraging cloud infrastructure to distribute malware.”

Related: Rust supply chain attack linked to North Korean hackers

Related: AmnesiaStealer macOS malware steals data and controls browser sessions

Related: Stealthy “City Forum” attacks target Salesforce and ServiceNow using custom toolset

Leave a Reply

Your email address will not be published. Required fields are marked *