# Three Banking Trojans, One Ugly Picture: The Mobile Fraud Ecosystem Is Maturing Fast


The arrest of five Grandoreiro operators in Brazil in early 2024 was supposed to be a turning point. Interpol, ESET, and Brazilian federal police called it a significant disruption. The malware's infrastructure was seized. Researchers published detailed teardowns. And then, within months, Grandoreiro was back — hitting banks in Latin America and Europe as if the takedown had never happened.


That resilience is worth keeping in mind as three banking trojans — Manic, Grandoreiro, and ToxicPanda 2.0 — are simultaneously drawing researcher attention. This isn't a coincidence. It's a snapshot of how professionalized financial malware has become, and why the standard playbook for disrupting it keeps falling short.


## Grandoreiro Won't Stay Down


Grandoreiro has been active since at least 2016. A decade is an eternity in malware years, and the gang behind it has used that time well. The trojan targets Windows systems, impersonating legitimate banking portals with overlay screens to capture credentials and one-time codes. Its operators work with a network of money mules across Spain, Portugal, Mexico, and Argentina — which is partly why law enforcement actions in one country barely dent the operation.


The current campaign shows the group has reconfigured around the 2024 disruption. New infrastructure, new phishing lures, and geographic pivots into markets where law enforcement coordination is slower. The overlay technique is mature but effective — banks have been fighting it for years without a clean solution.


What makes Grandoreiro durable isn't technical sophistication. It's the organizational model. The malware is reportedly run as a Malware-as-a-Service (MaaS) operation, with different criminal groups renting access to the infrastructure. When you arrest five people, you may have taken out one node in a franchise. The franchisor often isn't touched.


## ToxicPanda Grows Up


ToxicPanda first surfaced in late 2024, targeting Android users across Italy, Spain, Portugal, and parts of Asia. Researchers at Cleafy documented it as a relatively simple trojan by modern standards — capable of intercepting one-time passwords and performing account takeover through on-device fraud.


ToxicPanda 2.0 is a different matter. The updated version shows development investment: expanded device compatibility, more sophisticated anti-analysis capabilities, and improved persistence mechanisms. The fact that the group iterated quickly on a working product is the tell. This isn't a one-off experiment. There's a team, a roadmap, and presumably revenue funding the next version.


The on-device fraud model that ToxicPanda uses is particularly difficult for banks to counter. Traditional fraud detection flags transactions from new locations, new devices, or unusual behavioral patterns. On-device fraud executes from the victim's own phone, using their established session. The transaction looks like the customer did it. Because, from the bank's perspective, they kind of did.


## Manic: When Financial Fraud Meets Surveillance


The most concerning entrant in this trio is Manic. Where Grandoreiro and ToxicPanda are purpose-built financial fraud tools, Manic incorporates spyware capabilities — the kind that suggest the operators want more than access to a bank account. They want the whole device.


Spyware-enhanced banking trojans can harvest contact lists, intercept SMS messages, capture screenshots, record calls, and track location. That data has value beyond a single fraudulent transfer. It can be used for blackmail, sold to third parties, or leveraged to compromise additional accounts across services the victim uses.


This convergence of financial fraud and full-device surveillance is a troubling direction. It suggests either a more sophisticated threat actor (who needs the additional data for something), or a commoditization of spyware components that makes it cheap to add them to existing financial malware. Neither explanation is reassuring.


## The Latin America–Europe Pipeline


A pattern across all three trojans is the geographic arc from Latin America to Europe. Grandoreiro pioneered this path, refining techniques against less hardened Latin American banking infrastructure before hitting the higher-value targets in Spain and Portugal. ToxicPanda targets European banking customers. The operational model developed in one region gets exported when the group is ready to scale.


European banks have invested heavily in transaction monitoring and behavioral analytics, but they're not uniformly prepared for on-device fraud or the specific social engineering lures these campaigns use. Language barriers matter too — phishing campaigns crafted natively in Spanish or Portuguese are more convincing than machine-translated attacks from Eastern Europe.


## What Actually Works Against This


Banks have spent years layering authentication — SMS OTPs gave way to TOTP apps, which are now giving way to passkeys and hardware tokens. Banking trojans have kept pace at every step. The answer isn't to stop investing in authentication hardening; it's to pair it with out-of-band transaction verification that's genuinely independent of the compromised device.


For enterprise defenders and security teams protecting employees with business banking access:


  • Mobile device management matters here. Organizations with enforced MDM can detect sideloaded applications and unusual permission grants before an infection goes active.
  • Behavioral analytics on banking sessions should flag impossible action sequences — Grandoreiro-style overlays produce login patterns that differ from genuine user behavior.
  • OTP interception awareness means pushing high-value customers toward hardware tokens or passkey-based authentication that doesn't route through SMS.
  • Employee training on overlay attacks is underused. Users who know that a legitimate banking site will never ask them to re-enter credentials after a "timeout" are harder to fool.

  • ---


    ## HackWire Analysis


    The simultaneous spotlight on Manic, Grandoreiro, and ToxicPanda 2.0 tells us something researchers don't always say plainly: the banking trojan market is stratifying into tiers. Grandoreiro represents the mature, persistent franchise that absorbs law enforcement pressure and routes around it. ToxicPanda 2.0 represents the fast-moving mobile-focused challenger, iterating on a working product with real development velocity. Manic represents the surveillance-convergent threat that suggests operator ambitions beyond simple financial fraud.


    What's missing from most coverage is what this means for the law enforcement model. Takedown operations work well against centralized criminal infrastructure. Banking trojans — especially those operating as MaaS — are explicitly designed to survive them. Grandoreiro's 2024 comeback isn't a failure of the operation; it's proof that the operation addressed symptoms rather than the underlying structure. The money mule networks, the affiliate operators, the development teams — these don't disappear when five people in Goiânia get arrested.


    For defenders, the more actionable insight is that all three of these trojans require user interaction to land. Spearphishing emails, malicious APKs delivered through third-party stores, overlay attacks that depend on the user trusting what's on screen — the human vector remains primary. The security community keeps building better detection and authentication. But the trojans keep getting better at social engineering precisely because it works.


    The question worth asking isn't whether these specific trojans will be disrupted. Some will be. The question is what fills the vacuum. The answer, historically, is: something worse.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)