The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

Recent reports highlight the ongoing threat posed by several prominent banking Trojans, specifically identifying Manic, Grandoreiro, and ToxicPanda 2.0. These malware families are currently active, with Manic noted for its spyware capabilities, Grandoreiro for a persistent campaign across Latin America and Europe, and ToxicPanda 2.0 for an expanded operational scope. The collective activity of these Trojans underscores a sustained risk to financial institutions and their customers.
Manic is described as being equipped with spyware functionalities. This typically means the malware is designed not only to steal banking credentials but also to surreptitiously monitor user activity, capture keystrokes, take screenshots, and exfiltrate sensitive data from compromised systems. Such capabilities allow attackers to gain a comprehensive understanding of a victim's financial habits and access other personal information that could be leveraged for further fraud or identity theft.
Grandoreiro is noted for a persistent campaign targeting regions in Latin America and Europe. This geographic spread suggests a well-resourced and adaptable operation, likely employing various distribution methods such as phishing emails, malicious advertisements, or drive-by downloads. Banking Trojans like Grandoreiro often use overlay attacks, where fake login screens are displayed over legitimate banking applications to trick users into entering their credentials, which are then harvested by the attackers.
ToxicPanda 2.0 is reported to have an expanded malware operation. The expansion of a malware's scope can refer to several aspects, including an increase in the number of targeted victims, the adoption of new distribution vectors, or the incorporation of enhanced evasion techniques to bypass security defenses. This evolution often indicates successful campaigns that are being scaled up by their operators, potentially leveraging new vulnerabilities or refining their attack methodologies.
Mitigation against these types of banking Trojans generally involves a multi-layered security approach. For end-users, this includes maintaining up-to-date operating systems and applications, using reputable antivirus software, exercising caution with unsolicited emails and suspicious links, and enabling multi-factor authentication wherever possible. Organizations, particularly financial institutions, typically deploy advanced threat detection systems, implement strong network segmentation, and conduct regular security awareness training for employees to identify and report potential threats.
The continued prominence of banking Trojans like Manic, Grandoreiro, and ToxicPanda 2.0 illustrates the dynamic and persistent nature of cybercrime targeting financial assets. These threats constantly evolve, adapting their techniques and expanding their reach, requiring continuous vigilance and proactive security measures from both individuals and organizations to safeguard against financial fraud and data compromise.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.