Three Banking Trojans Are Quietly Draining Accounts Across Two Continents

Manic, Grandoreiro, and ToxicPanda 2.0 are targeting bank customers in Latin America and Europe. Here is what each one does and what ordinary people should watch for.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial shot of a dimly lit laptop screen displaying a generic corrupted PDF icon and a blurred Iberian-style banking web page reflection, warm
Share

Key points

  • Manic is a newly identified banking trojan, malicious software that secretly monitors your phone or computer to steal banking credentials, and it comes pre-loaded with spyware that records activity even when banking apps are closed.
  • Grandoreiro, a Brazilian criminal operation active since at least 2016, is running fresh campaigns targeting victims in Latin America and Europe.
  • ToxicPanda has released a second version, ToxicPanda 2.0, with expanded capabilities for intercepting one-time passwords sent by banks via text message.
  • All three are banking trojans, meaning their primary goal is emptying victims' accounts rather than demanding ransom.

Three separate criminal groups are competing for the same prize: access to your bank account. SecurityWeek reported this week on a cluster of banking trojans, which are programs criminals secretly install on a device to watch everything the victim types, including passwords and card numbers, that are gaining ground across two continents.

What are these three threats and who is behind them?

Each group operates independently, targets overlapping regions, and uses different tactics to get the same result: unauthorised transfers out of victims' accounts.

Malware Origin / Operator Primary Targets Notable Capability
Manic Unknown Europe, Latin America Built-in spyware module
Grandoreiro Brazilian cybercrime group Latin America, Europe Long-running, persistent campaigns
ToxicPanda 2.0 Likely China-linked Europe, Latin America Intercepts SMS one-time passwords

Manic is the newest name in the trio. It arrives bundled with spyware, software that silently records screen activity and keystrokes, meaning criminals can watch a victim fill in their banking details in real time. That persistent surveillance sets it apart from simpler credential-stealing tools.

Grandoreiro is the oldest of the three. Brazilian authorities and Interpol disrupted parts of its network in early 2024, but the group rebuilt and is running active campaigns again. It primarily spreads through phishing, where criminals send fake emails pretending to be tax authorities or utility companies to trick recipients into opening a malicious file.

ToxicPanda first appeared in late 2023. Version 2.0 adds a critical new trick: intercepting the one-time codes banks text to customers as a second layer of verification. Those codes are supposed to stop criminals even when they have a password. ToxicPanda 2.0 grabs the code before the customer can use it.

Should ordinary bank customers be worried?

Yes, but calmly. These campaigns are broad, not surgical. Criminals cast wide nets through fake emails and malicious app downloads, hoping a percentage of recipients clicks.

If you bank online, four habits cut your risk significantly. First, never open an email attachment from a sender you did not expect, even if the message looks official. Second, download apps only from your phone's official store, and check the developer name carefully before installing anything finance-related. Third, if your bank offers an authenticator app as a second login step rather than a text message code, switch to it: ToxicPanda intercepts texts, not app-generated codes. Fourth, review your account transactions at least twice a week. Unauthorised transfers that are caught within 24 hours are far easier for banks to reverse.

If your device starts behaving oddly, such as the battery draining fast, the screen lighting up without reason, or banking apps crashing, run a security scan with a reputable mobile security app and contact your bank directly using the number on the back of your card.

© 2026 Threat Vectr