Manic Android Trojan hits Ukrainian banks, Grandoreiro resurfaces in Latin America

Manic Android Trojan hits Ukrainian banks, Grandoreiro resurfaces in Latin America

Cybersecurity firms this week disclosed details about new and updated banking trojans targeting users worldwide. These malware strains enable operators to phish credentials, steal sensitive data, and remotely control compromised devices.

ThreatFabric detailed Manic, an Android malware that combines banking trojan and spyware capabilities. The malware has primarily targeted Ukraine, including banks, government services, and messaging applications. However, it has also been observed attacking Russian and European financial institutions, global cryptocurrency and fintech services, and military-focused messaging apps. Manic is distributed via malicious websites and droppers, allowing attackers to log keystrokes, display phishing screens, and remotely control the compromised phone for banking and cryptocurrency fraud. Additionally, Manic includes spyware features such as notification monitoring, location tracking, file harvesting, and remote device surveillance. ThreatFabric highlighted a particularly distinctive capability: an offline mesh relay that allows collected data to move through nearby infected devices over Wi-Fi Direct or Bluetooth when direct command-and-control server access is unavailable.

The Acronis Threat Research Unit warned that the Grandoreiro banking trojan remains active, continuing to focus on users in Latin America. Grandoreiro was also seen targeting Europe last year and continues to target Europe alongside North America. However, a recent campaign monitored by Acronis saw the bulk of attacks aimed at Mexico. Acronis noted that the trojan's operators are constantly refining their techniques, including the use of advanced social engineering and multi-stage infection chains to evade detection. The malware typically spreads through phishing emails with malicious attachments or links, and once installed, it can intercept SMS messages, steal banking credentials, and perform unauthorized transactions. Grandoreiro has been known to target over 300 financial institutions globally, with a particular emphasis on banks in Latin America, Spain, and Portugal. The Acronis report also highlighted that the trojan's code is frequently updated to bypass security measures, making it a persistent threat to both individual users and organizations.

Tags: Android
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate