تخطي إلى المحتوى الرئيسي
Cyber News Dark Reading 2 hours ago

ToxicPanda Banking Trojan Matures Into Enterprise Threat

Da
Dark Reading

An Android banking Trojan has resurfaced with a new variant that demonstrates a significant evolution toward full device compromise and persistent access, putting at risk not only mobile users but also the enterprise resources accessed from those devices.

ToxicPanda 2.0 expands substantially on its predecessor, adding 167 remote commands and broadening its targeting from 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications, according to recent research from Zimperium zLabs. The Trojan also adds more sophisticated techniques for compromising Android devices, including privilege escalation and shell-level access through Android's Wireless Debugging and Android Debug Bridge (ADB), as well as capabilities designed to maintain long-term persistence on infected devices.

ToxicPanda first emerged in November 2024, when it was observed taking over Android devices and facilitating fraudulent mobile banking transactions in Latin America, Italy, Portugal, and Spain. Its expansion into 16 countries and the addition of significantly more functionality indicate a more mature and capable threat than the initial version researchers encountered.

Related:Video Call Exploit Chains Two Flaws in Unisoc Modems

Overall, the updated version "demonstrates a significant expansion in targeting scope and capabilities," Zimperium zLabs researcher Vishnu Pratapagiri wrote in the report.

View Original Report

This intelligence was aggregated from Dark Reading.

Read on Source
Advertisement