Banking malware continues to evolve as cybercriminals develop more sophisticated ways to steal credentials, intercept authentication information, control devices, and conduct fraudulent financial activity.
Recent research has highlighted three banking trojan families receiving particular attention: Manic, Grandoreiro, and ToxicPanda 2.0. Their latest capabilities demonstrate how attackers are combining traditional phishing and credential theft with mobile device control, evasion techniques, cloud infrastructure, and abuse of legitimate platform features.
The activity is especially relevant for financial institutions, fintech companies, cryptocurrency platforms, businesses using mobile banking, and organizations that rely heavily on digital payments.
Manic Combines Banking Malware With Spyware
Manic is a recently identified Android threat that combines banking trojan capabilities with broader spyware functionality.
Researchers have observed the malware targeting financial institutions, government services, communication applications, fintech platforms, and cryptocurrency-related services, with activity particularly focused on Ukraine and extending into other European regions.
Manic can potentially monitor activity on an infected device and collect sensitive information such as:
• Login credentials
• Authentication codes
• Banking PINs
• Messages and notifications
• Files
• Device information
• Location information
• On-screen activity
One particularly concerning capability is its ability to move stolen information between nearby compromised devices.
Instead of depending entirely on a direct connection to attacker-controlled infrastructure, the malware can use nearby infected devices as relay points through wireless communication technologies.
This creates an additional challenge for defenders because conventional network-based monitoring may not always provide a complete picture of how stolen information moves between compromised devices.
Grandoreiro Continues to Adapt
Grandoreiro is a long-running banking trojan that has continued to operate despite previous disruption efforts.
Recent activity has focused heavily on Latin American targets, including Mexico, while the malware has also maintained activity across parts of Europe and North America.
One of the techniques associated with newer campaigns is DLL sideloading.
This technique takes advantage of legitimate software to load a malicious library. By hiding malicious execution behind trusted applications, attackers can make their activity harder for traditional security controls to identify.
Grandoreiro also incorporates anti-analysis capabilities designed to determine whether it is operating inside security research environments, virtual machines, or automated analysis systems.
These capabilities demonstrate an important trend in modern malware development.
Attackers are not simply trying to infect more devices. They are also attempting to identify security controls and avoid environments where their malware is likely to be detected or analyzed.
ToxicPanda 2.0 Expands the Mobile Attack Surface
ToxicPanda 2.0 represents another significant development in mobile banking malware.
The updated Android threat has expanded its targeting capabilities considerably and can interact with hundreds of financial, banking, e-wallet, and cryptocurrency applications across multiple countries.
Researchers identified 167 remote commands associated with the newer variant, along with capabilities for credential theft, device manipulation, and automated fraudulent activity.
The malware also abuses Android Accessibility Services and Wireless Debugging functionality.
This is important because the attack does not necessarily depend on exploiting a newly discovered operating system vulnerability. Instead, attackers can abuse legitimate device functionality after obtaining sufficient permissions.
ToxicPanda 2.0 has also been observed using techniques to capture device unlock credentials, potentially giving attackers a much greater level of control over compromised devices.
The campaign further demonstrates how attackers are incorporating cloud infrastructure into malware distribution, including the use of AWS-hosted resources.
Why These Threats Matter to Financial Institutions
The evolution of these banking trojans highlights a major challenge for financial organizations.
Attackers are increasingly targeting the complete digital transaction ecosystem rather than simply attempting to steal a username and password.
A compromised mobile device can potentially expose:
• Banking credentials
• One-time authentication codes
• Payment information
• Cryptocurrency wallets
• Personal information
• Corporate applications
• Authentication sessions
• Device credentials
For banks and financial service providers, this creates risks that extend beyond individual customers.
A successful mobile malware campaign can contribute to account takeover, fraudulent transactions, identity theft, financial losses, regulatory exposure, and reputational damage.
Mobile Security Can No Longer Be an Afterthought
Many organizations have invested heavily in protecting corporate endpoints, servers, cloud environments, and networks.
However, employees and customers increasingly interact with financial services through mobile devices.
This makes mobile application and mobile endpoint security an essential part of modern cybersecurity strategy.
Organizations should consider:
• Mobile threat detection and response
• Mobile application security testing
• Strong authentication controls
• Device integrity monitoring
• Protection against malicious overlays
• Detection of unauthorized Accessibility Service changes
• Monitoring of developer options and wireless debugging
• Restrictions on application sideloading
• Secure mobile application development
• Behavioral fraud detection
• Continuous threat intelligence
Security teams should also pay close attention to unusual changes in device permissions and authentication behavior.
The Growing Risk of Legitimate Feature Abuse
One of the most important lessons from these campaigns is that attackers do not always need to exploit a software vulnerability.
They can abuse legitimate capabilities.
Accessibility services, wireless debugging, legitimate applications, cloud hosting, remote administration features, and trusted software can all become part of an attack chain when improperly controlled.
This creates a challenge for traditional security models.
Blocking every legitimate feature is neither practical nor desirable.
Instead, organizations need stronger governance around who can activate sensitive functionality, which applications can receive elevated permissions, and what behavior should trigger security alerts.
What Organizations Can Do
Financial institutions and other organizations exposed to mobile banking threats should adopt a layered security approach.
Key measures include:
• Enforcing strong multifactor authentication
• Monitoring account behavior for unusual transactions
• Restricting application sideloading
• Monitoring privileged mobile permissions
• Detecting unauthorized developer options
• Monitoring wireless debugging activity
• Implementing mobile threat defense
• Conducting application penetration testing
• Performing threat modeling for mobile applications
• Monitoring third party applications and dependencies
• Strengthening endpoint detection capabilities
• Conducting regular phishing and social engineering assessments
• Maintaining current threat intelligence
• Establishing incident response procedures for mobile compromise
Security teams should also assume that credentials can eventually be compromised and implement controls that detect suspicious activity after authentication.
Protecting Customers and Digital Financial Services
The banking industry is undergoing rapid digital transformation, with mobile applications, digital wallets, instant payments, cryptocurrency services, and online banking becoming increasingly important.
That transformation creates significant opportunities for customers and businesses, but it also expands the attack surface.
Financial organizations need to secure both the technology and the transaction behavior surrounding it.
Security programs should therefore combine application security, mobile security, identity protection, fraud detection, threat intelligence, and continuous monitoring.
Conclusion
The activity surrounding Manic, Grandoreiro, and ToxicPanda 2.0 demonstrates that banking malware is becoming more capable, adaptive, and difficult to detect.
The latest campaigns combine credential theft, device surveillance, evasion, remote control, legitimate feature abuse, and cloud-based infrastructure to increase the chances of successful financial attacks.
For financial institutions, fintech organizations, cryptocurrency platforms, retailers, and businesses supporting digital payments, mobile security must become an integral part of the broader cybersecurity strategy.
Organizations that continuously monitor mobile threats, control privileged device capabilities, strengthen authentication, test applications, and prepare for account takeover scenarios will be better positioned to protect customers and reduce financial cyber risk.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
In addition, COE Security helps organizations strengthen mobile and financial technology security through mobile application penetration testing, API security testing, application security assessments, threat intelligence, vulnerability management, identity and access security, fraud risk assessments, secure software development, cloud security assessments, third party risk assessments, and incident response readiness.
For financial services, banking, fintech, cryptocurrency, retail, healthcare, manufacturing, government, telecommunications, and technology organizations, COE Security helps identify vulnerabilities, protect sensitive information, strengthen digital applications, improve threat detection, and support cybersecurity and compliance requirements.
Our security approach helps organizations address emerging threats across applications, mobile platforms, cloud environments, networks, connected devices, and AI-powered systems.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.
Click to read our LinkedIn feature article