ToxicPanda Banking Trojan Infects Over 1,500 Android Smartphones, Targets 16 Banks: Report

Threat actors can use ToxicFraud banking trojan to perform on-device fraud (ODF) on a victim's smartphone.

Advertisement
Highlights
  • ToxicPanda is a recently detected Android banking trojan
  • Users are prompted to install the trojan using social engineering
  • The ToxicPanda trojan can gain access to a user's bank accounts
ToxicPanda Banking Trojan Infects Over 1,500 Android Smartphones, Targets 16 Banks: Report

Cleafy's Threat Intelligence team said traditional malware scanners were unable to detect ToxicPanda

Photo Credit: Pixabay/ @neotam

ToxicPanda — a banking trojan that is believed to be in an early stage of development — has been detected by security researchers in Europe and Latin America. It is believed to be derived from another banking trojan detected in 2023, and is used to remotely take over accounts on compromised phones, allowing attackers to transfer funds while bypassing security measures aimed at stopping suspicious transactions. ToxicPanda was reportedly found on over 1,500 devices, while targeting users of 16 banking institutions.

Researchers at Cleafy's Threat Intelligence detected a new Android malware in October that they previously detected as TgToxic, another banking trojan that was actively used in Southeast Asia and was identified by the group last year. The researchers found that the new sample did not contain capabilities from TgToxic, and that the code was not similar to the original trojan.

toxicpanda disguise apps cleafy toxicpanda

The ToxicPanda trojan is disguised as popular applications
Photo Credit: Cleafy

 

As a result, the researchers started to track the newly detected remote access trojan (RAT) as ToxicPanda and warns that the malware can lead to account takeover (ATO) after a victim's device is infected. Cleafy's Threat Intelligence team also says that by opting for manual distribution (sideloading, using social engineering), threat actors (TA) can circumvent a bank's security measures that are used to keep users safe.

In order to access almost all information on a user's device, the malware exploits the accessibility service on Android, allowing it to capture data from all apps. It is also capable of sidestepping two-factor authentication (such as OTPs) by capturing the contents of the screen. 

The creators of the ToxicPanda malware are Chinese speakers, according to the researchers. Over 1,500 devices were infected with the ToxicPanda trojan and users from Italy were the most impacted — more than 50 percent of all infected devices. Other impacted locations include Portugal, Spain, France, and Peru. Customers of 16 banks were reportedly targeted by the TAs using the ToxicPanda trojan.

The researchers also point out that current antivirus solutions have failed to detect these threats, which suggests the need for a "proactive, real-time detection system". A botnet of infected devices was also spotted in use in Europe and Latin American countries, which suggests that the Chinese-based TAs are now turning their attention to other markets. 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

David Delima

As a writer on technology with Gadgets 360, David Delima is interested in open-source technology, cybersecurit... more

Advertisement
Popular Mobile Brands
  1. Vivo Y300 5G's India Launch Date Announced; Design Revealed
  2. Vivo V40e Review: Easy on the Eyes
  3. Nothing OS 3.0 Open Beta 2 Update Rolls Out With These Features
  4. OpenAI Might Soon Launch AI Agents That Can Control Your Computer
  5. Xiaomi Is Reportedly Working on a Pair of AI Glasses to Compete With Meta
  6. Vivo X200 Series Global Launch Date Revealed
  1. Ancient Fossil Bird Skull Reveals Roots of Avian Intelligence, Finds New Study
  2. NASA Data Empowers Global Response to Rising Sea Levels, Here's What You Need to Know
  3. Reliance and Disney Complete Merger to Create a Rs. 70,352 Crore Joint Venture
  4. Shift Up Says Its Considering Launching Stellar Blade on PC in 2025
  5. Vivo X200 Series Global Launch Date Confirmed; Mini Model May Remain Exclusive to China
  6. 12,000-Year-Old Doughnut-Shaped Pebbles in Israel May Be Early Evidence of Wheel Technology
  7. India's CCPA to Probe E-Scooter Maker Ola Electric Over Service, Product Standards
  8. Gemini in Gmail Gets Integration With Google Calendar App, Lets Users Ask Date-Based Queries
  9. Realme Narzo 70 Curve Tipped to Launch in India Next Month; Price Range Leaked
  10. Crypto Taxes Generated $78 Million in Kenya, Authorities Target Over $460 Million
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2024. All rights reserved.
Trending Products »
Latest Tech News »