Categories: Gadgets360

ToxicPanda Banking Trojan Infects Over 1,500 Android Smartphones, Targets 16 Banks: Report

ToxicPanda — a banking trojan that is believed to be in an early stage of development — has been detected by security researchers in Europe and Latin America. It is believed to be derived from another banking trojan detected in 2023, and is used to remotely take over accounts on compromised phones, allowing attackers to transfer funds while bypassing security measures aimed at stopping suspicious transactions. ToxicPanda was reportedly found on over 1,500 devices, while targeting users of 16 banking institutions.

Researchers at Cleafy’s Threat Intelligence detected a new Android malware in October that they previously detected as TgToxic, another banking trojan that was actively used in Southeast Asia and was identified by the group last year. The researchers found that the new sample did not contain capabilities from TgToxic, and that the code was not similar to the original trojan.

The ToxicPanda trojan is disguised as popular applications
Photo Credit: Cleafy

 

As a result, the researchers started to track the newly detected remote access trojan (RAT) as ToxicPanda and warns that the malware can lead to account takeover (ATO) after a victim’s device is infected. Cleafy’s Threat Intelligence team also says that by opting for manual distribution (sideloading, using social engineering), threat actors (TA) can circumvent a bank’s security measures that are used to keep users safe.

In order to access almost all information on a user’s device, the malware exploits the accessibility service on Android, allowing it to capture data from all apps. It is also capable of sidestepping two-factor authentication (such as OTPs) by capturing the contents of the screen. 

The creators of the ToxicPanda malware are Chinese speakers, according to the researchers. Over 1,500 devices were infected with the ToxicPanda trojan and users from Italy were the most impacted — more than 50 percent of all infected devices. Other impacted locations include Portugal, Spain, France, and Peru. Customers of 16 banks were reportedly targeted by the TAs using the ToxicPanda trojan.

The researchers also point out that current antivirus solutions have failed to detect these threats, which suggests the need for a “proactive, real-time detection system”. A botnet of infected devices was also spotted in use in Europe and Latin American countries, which suggests that the Chinese-based TAs are now turning their attention to other markets. 

Recent Posts

Beyoncé’s NFL Christmas Halftime Show Now Streaming on Netflix: Everything You Need to Know

Beyoncé's much-anticipated halftime performance, part of Netflix's NFL Christmas Gameday event, is set to release…

10 months ago

Scientists Predict Under Sea Volcano Eruption Near Oregon Coast in 2025

An undersea volcano situated roughly 470 kilometers off Oregon's coastline, Axial Seamount, is showing signs…

10 months ago

Organic Molecules in Space: A Key to Understanding Life’s Cosmic Origins

As researchers delve into the cosmos, organic molecules—the building blocks of life—emerge as a recurring…

10 months ago

The Secret of the Shiledars OTT Release Date Announced: What You Need to Know

Director Aditya Sarpotdar, following his successful venture "Munjya," has announced the release of his treasure…

10 months ago

Anne Hathaway’s Mothers’ Instinct Now Streaming on Lionsgate Play

The psychological thriller Mothers' Instinct, featuring Anne Hathaway, Jessica Chastain, and Kelly Carmichael, delves into…

10 months ago

All We Imagine As Light OTT Release Date: When and Where to Watch it Online?

Payal Kapadia's award-winning film, All We Imagine As Light, will soon be available for streaming,…

10 months ago