Android Banking Trojans Add Mesh Relay and ADB Abuse for Evasion
Three banking trojans released updates that prioritize C2 resilience and detection evasion over new infection vectors. Technical details from ThreatFabric, Acronis, and Zimperium reveal shared tactics with prior supply-chain incidents. Continued monitoring of command counts and infrastructure reuse will determine whether these families merge or remain distinct.
Next quarter will test whether mesh relay traffic volume triggers carrier detection or if AWS bucket takedowns force a shift to other CDNs. Independent monitoring of command counts and target list growth provides the clearest signal of operational continuity.
Zimperium: ToxicPanda 2.0 will appear in 3 new European countries with active AWS buckets by end of Q2 2025 if command count exceeds 200.
Sources (3)
- [1]ThreatFabric Manic Report(https://www.threatfabric.com/blog/manic-android-trojan-mesh-relay)
- [2]Acronis Grandoreiro Analysis(https://www.acronis.com/en-us/cyber-protection-center/grandoreiro-dff-sideloading)
- [3]Zimperium ToxicPanda 2.0(https://www.zimperium.com/blog/toxicpanda-2-0-adb-abuse)