Live Cybersecurity News Ticker | Codekeeper

Three Banking Trojans — Manic, Grandoreiro, and ToxicPanda 2.0 — Are Actively Targeting Users Worldwide

Written by Content Team | Aug 24, 2026, 7:26:45 AM

Cybersecurity researchers are flagging three dangerous banking trojans making the rounds. Manic, an Android malware detailed by ThreatFabric, combines banking fraud with spyware and targets Ukraine, Russia, and European financial institutions — even using Bluetooth and Wi-Fi to relay stolen data when internet access is unavailable.

Grandoreiro, a decade-old Windows trojan from Brazil, remains active per the Acronis Threat Research Unit, though at considerably lower volume than before a January 2024 law enforcement takedown. It's still hitting Latin America, with a more limited presence in Europe, and recent attacks have focused on Mexico. The trojan now hides inside a legitimate file-finder app to dodge detection.

ToxicPanda 2.0, flagged by Zimperium, is the biggest upgrade — now targeting 349 financial apps across 16 countries and delivering payloads through Amazon AWS.

Source: SecurityWeek