ToxicPanda: A new Android malware threatening bank accounts globally

ISGroup Cybersecurity

A new malware known as ToxicPanda is actively targeting Android devices and banking applications worldwide, posing a serious risk to users’ financial security. This malware disguises itself as trusted applications such as Google Chrome and banking apps, making it difficult for users to detect. ToxicPanda’s ability to gain remote access to infected devices allows attackers to initiate unauthorized financial transactions, leaving victims exposed to significant economic losses.

Date2024-11-08 16:45:02
Information
  • Banking
  • Ransomware
  • Active Exploitation

Technical Summary

ToxicPanda is a financial trojan targeting Android devices, spreading through applications installed from untrusted sources outside of official stores. Originating from an older malware family called TgToxic, this new variant bypasses banking security by intercepting one-time passwords and utilizing On-Device Fraud (ODF) techniques. The malware primarily affects users in Europe and Latin America, with the highest infection rates reported in Italy, Portugal, Hong Kong, Spain, and Peru.

Recommendations

To protect themselves from ToxicPanda, Android users should:

  • Download applications only from official sources.
  • Regularly update the operating system and applications to ensure they receive the latest security patches.
  • Carefully monitor bank accounts for suspicious transactions and enable notifications to be alerted immediately of unauthorized activity.
  • Avoid installing apps from unknown websites or installation prompts that appear outside of official stores.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert