LIVE · cybersecurity feed
Live wire
CVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on HostCISA orders feds to patch actively exploited TrueConf Server flawsCVE-2026-69836 · Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

zeroday.news ·

Recent reports highlight the ongoing threat posed by several prominent banking Trojans, specifically identifying Manic, Grandoreiro, and ToxicPanda 2.0. These malware families are currently active, with Manic noted for its spyware capabilities, Grandoreiro for a persistent campaign across Latin America and Europe, and ToxicPanda 2.0 for an expanded operational scope. The collective activity of these Trojans underscores a sustained risk to financial institutions and their customers.

Manic is described as being equipped with spyware functionalities. This typically means the malware is designed not only to steal banking credentials but also to surreptitiously monitor user activity, capture keystrokes, take screenshots, and exfiltrate sensitive data from compromised systems. Such capabilities allow attackers to gain a comprehensive understanding of a victim's financial habits and access other personal information that could be leveraged for further fraud or identity theft.

Grandoreiro is noted for a persistent campaign targeting regions in Latin America and Europe. This geographic spread suggests a well-resourced and adaptable operation, likely employing various distribution methods such as phishing emails, malicious advertisements, or drive-by downloads. Banking Trojans like Grandoreiro often use overlay attacks, where fake login screens are displayed over legitimate banking applications to trick users into entering their credentials, which are then harvested by the attackers.

ToxicPanda 2.0 is reported to have an expanded malware operation. The expansion of a malware's scope can refer to several aspects, including an increase in the number of targeted victims, the adoption of new distribution vectors, or the incorporation of enhanced evasion techniques to bypass security defenses. This evolution often indicates successful campaigns that are being scaled up by their operators, potentially leveraging new vulnerabilities or refining their attack methodologies.

Mitigation against these types of banking Trojans generally involves a multi-layered security approach. For end-users, this includes maintaining up-to-date operating systems and applications, using reputable antivirus software, exercising caution with unsolicited emails and suspicious links, and enabling multi-factor authentication wherever possible. Organizations, particularly financial institutions, typically deploy advanced threat detection systems, implement strong network segmentation, and conduct regular security awareness training for employees to identify and report potential threats.

The continued prominence of banking Trojans like Manic, Grandoreiro, and ToxicPanda 2.0 illustrates the dynamic and persistent nature of cybercrime targeting financial assets. These threats constantly evolve, adapting their techniques and expanding their reach, requiring continuous vigilance and proactive security measures from both individuals and organizations to safeguard against financial fraud and data compromise.

malwarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2024-3094high

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are increasingly targeting the software development lifecycle (SDLC) supply chain by compromising developer tools, CI/CD pipelines, and open-source packages. Recent attacks like the ChainDrop npm worm demonstrate sophisticated methods to steal credentials, backdoor developer environments, and propagate malware. Securing the SDLC requires a shift from reactive code scanning to strict execution control and continuous visibility across developer endpoints, build pipelines, and cloud runtimes.

breach

AWS Security makes an inscrutable choice

Quarantining leaked credentials is not good enough

cloud security

Cloudflare Launches Bot Preference Sync for AI Traffic Management

Cloudflare has introduced Bot Preference Sync, a new feature designed to simplify the management of AI bot traffic. This tool automatically updates a website's robots.txt file to align with the user's AI bot configuration settings. The goal is to prevent discrepancies between stated preferences and enforced rules, ensuring better control over how AI crawlers access and use website content.

ai

Say it once: introducing Bot Preference Sync

Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.

patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.