s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.toxic_panda

📛 Threat Title

Malware family: ToxicPanda

Category: ToxicPanda First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.toxic_panda`. Printable name: ToxicPanda.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:build38.com

    The malware leverages accessibility service abuse, remote control capabilities, and interception of one-time passwords (OTPs) to bypass modern security measures, including multi-factor authentication (MFA). Originating from the TgToxic malware family , ToxicPanda retains foundational similarities while introducing significant code divergences.

  • web:cirt.gy

    Description TgToxic (also known as ToxicPanda ) is a sophisticated Android banking trojan that continues to evolve with advanced anti-analysis capabilities. Initially documented by Trend Micro in 2023, the malware has expanded its reach beyond Taiwan, Thailand, and Indonesia to target users in Italy, Portugal, Hong Kong, Spain, and Peru. The latest iteration, discovered by Intel 471 ...

  • web:cybercory.com

    In a recent discovery, cybersecurity researchers have identified a new Android banking trojan called " ToxicPanda ," originating in Asia and now spreading across Europe and Latin America. Initially related to a trojan family known as TgToxic, ToxicPanda has emerged as a distinct threat with unique attack patterns. Its primary objective is to conduct account takeover (ATO) attacks, exploiting ...

  • web:cybersecuritynews.com

    The malware shows particular affinity for mid-range Android devices, with Samsung A series, Xiaomi Redmi, and Oppo A models comprising the majority of infected devices, though premium models including Samsung S series devices have also been compromised. Advanced Persistence and Evasion Mechanisms ToxicPanda employs sophisticated persistence techniques that make traditional removal methods ...

  • web:infosecbulletin.com

    The Cleafy team notes, "While it shares some bot command similarities with the TgToxic family , the code diverges considerably from its original source". This divergence led to the malware being reclassified as ToxicPanda . Cleafy's Threat Intelligence team analysts identified the following icons during this investigation.

  • web:malpedia.caad.fkie.fraunhofer.de

    ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024. It shows similarity to the TgToxic campaign, but appears to be a new development rather than a derivative. The threat actors are likely Chinese speakers. ToxicPanda initially made use of hardcoded C2 domains only, but started to incorporate a DGA in late 2024.

  • web:thehackernews.com

    Cybersecurity researchers have discovered an updated version of an Android malware called TgToxic (aka ToxicPanda ), indicating that the threat actors behind it are continuously making changes in response to public reporting. "The modifications seen in the TgToxic payloads reflect the actors' ongoing surveillance of open source intelligence and demonstrate their commitment to enhancing the ...

  • web:trufae.github.io

    In late October 2024, cybersecurity researchers identified a new Android banking trojan—dubbed ToxicPanda . Although initially classified as a member of the TgToxic family due to similarities in command syntax, subsequent analysis revealed significant code differences that warranted reclassification as a distinct threat. In this post, we explore ToxicPanda's origin, infection methods ...

  • web:www.bitsight.com

    What is ToxicPanda ? Bitsight Trace dives into detail on the banking malware , from impact breadth, delivery, technical analysis, and more. Learn more now.

  • web:www.cleafy.com

    Discover Cleafy's in-depth analysis of a new Android banking Trojan campaign, ToxicPanda , initially linked to TgToxic. Our findings reveal a sophisticated fraud operation targeting European and LATAM banks, using On-Device Fraud (ODF) tactics to execute account takeovers. Learn about ToxicPanda's evasion techniques and its early-stage development as it aims to bypass banking security measures.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.