Right now, three separate Android banking trojan operations are running against victims on two continents. Manic is quietly harvesting credentials with built-in spyware features. Grandoreiro, a campaign security researchers have been tracking for years, just won’t die and is back hitting targets across Latin America and Europe. And ToxicPanda 2.0 has expanded its remote-access capabilities well past what the original version could do. None of these are proof-of-concept research. They’re active, monetized, and running in parallel. That’s the state of mobile cybersecurity heading into the back half of 2026: not one big outbreak, but a permanent background hum of financial malware that never fully clears.

Three Campaigns, One Overlapping Playbook
Strip away the branding and these three trojans are running the same core attack. They get onto a device through a sideloaded app, a fake update prompt, or a phishing link that leads to an APK instead of a browser session. Once installed, they abuse Android’s accessibility service to read what’s on screen, log keystrokes, and inject fake login overlays on top of real banking apps. ToxicPanda 2.0’s upgrade adds better screen-sharing and remote-control features, which means an operator can watch a victim authenticate and then take the session over live, MFA prompt and all. Grandoreiro’s persistence comes from constant re-packaging to dodge signature detection. Manic leans harder into surveillance, pulling contacts, SMS, and app usage data alongside the banking credentials.
None of this is exotic. It’s the same overlay-and-abuse-accessibility model that’s worked for half a decade. What’s changed is scale and coordination. These operators are running polished, maintained software with update cycles, not single-shot malware kits. Treating any one of them as a solved problem because a specific IOC list got published is how the next variant walks right back in.
The Fine Print: $400 Million and Business as Usual
The same week these trojans made headlines, TikTok agreed to pay $400 million to settle a U.S. Department of Justice lawsuit over child privacy violations. $300 million lands immediately, another $100 million once a prior consent decree gets vacated. It’s a real number. It’s also a number a company TikTok’s size absorbs without changing how it operates day to day.
Put these two stories next to each other and you get an uncomfortable but useful comparison. On one side, criminal malware operators face essentially zero deterrent and keep multiple campaigns running simultaneously with no meaningful law enforcement disruption in sight. On the other, a legitimate platform gets caught violating privacy law at massive scale and pays what amounts to a cost of doing business. Neither side is being meaningfully stopped by the accountability layer that’s supposed to protect the device in your employee’s or customer’s pocket. If you’re building a security program that assumes regulation, app store vetting, or law enforcement will handle the mobile threat landscape for you, both of these stories argue otherwise. The device is yours to defend, because nobody upstream is going to do it for you on a timeline that matters.

What Actually Stops an Overlay Attack
If your organization has BYOD policy exposure, a mobile banking app, or a workforce that authenticates on personal Android devices, the fix isn’t waiting for Google Play to catch the next repackaged APK. It’s building layered controls that assume malware will land on some fraction of devices no matter what you do upstream.
- Restrict accessibility service permissions through MDM policy for managed devices, and flag any app requesting accessibility access outside an approved allowlist.
- Block sideloading and unknown-sources installation on corporate-enrolled devices at the OS policy level, not just with a warning banner.
- Push MFA methods that resist overlay and session hijacking, meaning hardware keys or app-based push with number matching, not SMS codes an overlay can capture.
- Monitor for anomalous login patterns from mobile sessions, including geographic mismatches and device fingerprint changes right after a login event.
- Require banking and financial apps to run Play Integrity or equivalent device attestation checks before allowing a session to proceed.
None of this requires exotic tooling. It requires actually enforcing the mobile management policies most organizations already have on paper and never turn on because they generate help desk tickets.
Building Threat Detection That Doesn’t Wait for a Vendor Patch
The reason Grandoreiro keeps coming back after years of takedown attempts is that most defenses are reactive: block the known hash, block the known C2 domain, wait for the next repack. That’s not threat detection, that’s inventory management. Real defense in depth on mobile means behavioral monitoring that flags accessibility service abuse and screen-overlay behavior regardless of which campaign is running it this month.
On the network side, the same logic applies to brute-force protection and firewall rules protecting the backend systems these trojans ultimately target. If an attacker successfully phishes credentials on a mobile device, the next control that matters is whether your login infrastructure can catch the resulting authentication attempt as anomalous, whether that’s unusual velocity, an unfamiliar ASN, or a device fingerprint that’s never been seen before on that account. Incident response plans built around “how do we get someone off a device” need a parallel track for “how do we invalidate the sessions and tokens that account touched before it was cleaned up.” Security hardening on the endpoint and threat-protection on the backend have to move together, because a trojan that only steals a password once is still dangerous for weeks if nobody rotates the tokens it exposed.
Sources
- Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
