ToxicPanda Banking Trojan Infects Over 1,500 Android Smartphones, Targets 16 Banks: Report

Threat actors can use ToxicFraud banking trojan to perform on-device fraud (ODF) on a victim's smartphone.

Advertisement
Written by David Delima | Updated: 7 November 2024 12:53 IST
Highlights
  • ToxicPanda is a recently detected Android banking trojan
  • Users are prompted to install the trojan using social engineering
  • The ToxicPanda trojan can gain access to a user's bank accounts

Cleafy's Threat Intelligence team said traditional malware scanners were unable to detect ToxicPanda

Photo Credit: Pixabay/ @neotam

ToxicPanda — a banking trojan that is believed to be in an early stage of development — has been detected by security researchers in Europe and Latin America. It is believed to be derived from another banking trojan detected in 2023, and is used to remotely take over accounts on compromised phones, allowing attackers to transfer funds while bypassing security measures aimed at stopping suspicious transactions. ToxicPanda was reportedly found on over 1,500 devices, while targeting users of 16 banking institutions.

Researchers at Cleafy's Threat Intelligence detected a new Android malware in October that they previously detected as TgToxic, another banking trojan that was actively used in Southeast Asia and was identified by the group last year. The researchers found that the new sample did not contain capabilities from TgToxic, and that the code was not similar to the original trojan.

Advertisement

The ToxicPanda trojan is disguised as popular applications
Photo Credit: Cleafy

Advertisement

 

As a result, the researchers started to track the newly detected remote access trojan (RAT) as ToxicPanda and warns that the malware can lead to account takeover (ATO) after a victim's device is infected. Cleafy's Threat Intelligence team also says that by opting for manual distribution (sideloading, using social engineering), threat actors (TA) can circumvent a bank's security measures that are used to keep users safe.

Advertisement

In order to access almost all information on a user's device, the malware exploits the accessibility service on Android, allowing it to capture data from all apps. It is also capable of sidestepping two-factor authentication (such as OTPs) by capturing the contents of the screen. 

The creators of the ToxicPanda malware are Chinese speakers, according to the researchers. Over 1,500 devices were infected with the ToxicPanda trojan and users from Italy were the most impacted — more than 50 percent of all infected devices. Other impacted locations include Portugal, Spain, France, and Peru. Customers of 16 banks were reportedly targeted by the TAs using the ToxicPanda trojan.

Advertisement

The researchers also point out that current antivirus solutions have failed to detect these threats, which suggests the need for a "proactive, real-time detection system". A botnet of infected devices was also spotted in use in Europe and Latin American countries, which suggests that the Chinese-based TAs are now turning their attention to other markets. 

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Demon Slayer: Infinity Castle Movie OTT Release Date: When and Where to Watch it Online?
  2. OnePlus Nord 6 Launched in India With 9,000mAh Battery at This Price
  3. Fujifilm Launches XT-30 III Mirrorless Camera in India at This Price
  4. Redmi Note 15 SE 5G With 5,800mAh Battery Goes on Sale in India: See Offers
  5. Here's When the Realme Buds T500 Pro Will Launch in India
  6. Lenovo Launches New IdeaPad 5 2-in-1 and Yoga Series Laptops in India
  7. OnePlus Nord 6 vs Redmi Note 15 Pro+ 5G vs Nothing Phone 4a Pro Compared
  8. Vivo X300 FE Launch Timeline Leaked Alongside These Three Colourways
  9. Best Laser Printers With Automatic Duplex Printing in India
  10. Apple's First Foldable Is Reportedly on Track to Launch Later This Year
  1. Google Chrome Updated With Vertical Tabs Feature and Full Page Reading Mode
  2. Apple’s First Foldable Reportedly on Track for September Launch Despite Claims of Production Delays
  3. Google Improves AI-Powered Shopping Experience in India With Gemini, Search, and Circle to Search Updates
  4. Motorola Edge 60 Fusion, Moto G57 Power and G35 Price in India Hiked, Tipster Claims
  5. Rubin Observatory Discovers Over 11,000 Asteroids Within Weeks of Imaging
  6. OnePlus Nord 6 Launched in India With Snapdragon 8s Gen 4 SoC, 9,000mAh Battery: Price, Specifications
  7. Sony Reportedly Preparing 'The ColleXion' 1000X-Series Headphones; Price, Launch Date Leaked
  8. Vivo X500 Pro Max Tipped to Feature Next-Generation Sony Camera Sensor
  9. Argentine Banks Reportedly Begin Testing JPMorgan’s JPM Coin for Faster Settlements
  10. Solana Foundation Launches STRIDE Network to Strengthen DeFi Security
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.