Three Banking Trojans Are Quietly Draining Accounts Across Two Continents

Manic, Grandoreiro, and ToxicPanda 2.0 are targeting bank customers in Latin America and Europe. Here is what each one does and what ordinary people should watch for.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A banking website login screen displayed on a computer monitor with warning alerts visible, alongside banking documents and a mobile phone on a desk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Manic is a newly identified banking trojan, malicious software that secretly monitors your phone or computer to steal banking credentials, and it comes bundled with spyware that records activity even when banking apps are closed.
  • Grandoreiro, a Brazilian criminal operation active since at least 2016, is running fresh campaigns targeting victims in Latin America and Europe.
  • ToxicPanda 2.0 has expanded capabilities for intercepting one-time passwords sent by banks via text message.
  • All three are banking trojans, meaning their primary goal is emptying victims' accounts rather than demanding ransom.

Three separate criminal groups are competing for the same prize: access to your bank account. SecurityWeek reported this week on a cluster of banking trojans, programs criminals secretly install on a device to watch everything the victim types including passwords, that are gaining ground across two continents.

What are these three threats and who is behind them?

Each group operates independently with different tactics and targets overlapping regions, all to achieve the same result: unauthorised transfers out of victims' accounts.

Malware Origin / Operator Primary Targets Notable Capability
Manic Unknown Europe, Latin America Built-in spyware module
Grandoreiro Brazilian cybercrime group Latin America, Europe Long-running, persistent campaigns
ToxicPanda 2.0 Likely China-linked Europe, Latin America Intercepts SMS one-time passwords

Manic is the newest name in the trio. It arrives bundled with spyware, software that silently records screen activity and keystrokes, meaning criminals can watch a victim fill in their banking details in real time. We first covered Manic on 20 August in a report noting it targets 169 apps and can relay stolen data through nearby infected devices over Wi-Fi Direct or Bluetooth. That persistent surveillance sets it apart from simpler credential-stealing tools.

Grandoreiro is the oldest of the three. Brazilian authorities and Interpol disrupted parts of its network in early 2024, but the group rebuilt and is running active campaigns again. It spreads primarily through phishing, fake emails pretending to be tax authorities or utility companies, to trick recipients into opening a malicious file.

ToxicPanda first appeared in late 2023. Version 2.0 adds a critical new capability: intercepting the one-time codes banks text to customers as a second layer of verification. Those codes are supposed to stop criminals even when they have a password. Our earlier story on ToxicPanda 2.0 found it carries 167 remote commands and a PIN-grabbing routine. ToxicPanda 2.0 grabs the code before the customer can use it.

Should ordinary bank customers be worried?

Yes, but calmly. These campaigns are broad, not surgical. Criminals cast wide nets through fake emails and malicious app downloads, hoping a percentage of recipients clicks.

If you bank online, four habits cut your risk. Don't open an email attachment from a sender you didn't expect, even if the message looks official. Download apps only from your phone's official store, and check the developer name carefully before installing anything finance-related. If your bank offers an authenticator app as a second login step rather than a text message code, switch to it: ToxicPanda intercepts texts, not app-generated codes. Review your account transactions regularly, because transfers caught early are far easier for banks to reverse.

If your device starts behaving oddly, such as the battery draining fast, the screen lighting up without reason, or banking apps crashing, run a security scan with a reputable mobile security app and contact your bank directly using the number on the back of your card.

© 2026 Threat Vectr