s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.tgtoxic

📛 Threat Title

Malware family: TgToxic

Category: TgToxic First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.tgtoxic`. Printable name: TgToxic.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.tgtoxic VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.tgtoxic

IOC database

Type
domain
Value
apk.tgtoxic
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.tgtoxic

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/apk.tgtoxic

References (1)

Remediations (10)

  • web:cloudindustryreview.com

    The emergence of the new TgToxic banking Trojan variant marks a significant evolution in cyber threats, showcasing advanced anti-analysis features designed to evade detection and complicate forensic investigations. This sophisticated malware targets financial institutions and their customers, employing innovative techniques to bypass security measures and maintain persistence on infected ...

  • web:ethicalhackingnews.substack.com

    A new variant of the Android banking trojan TgToxic has emerged with advanced anti-analysis upgrades, making it increasingly difficult for security tools to detect. This article provides an in-depth look at the evolution of TgToxic , exploring its origins, updates, and the various techniques used to evade detection. The TgToxic banking trojan has evolved significantly, with new malware variants ...

  • web:hatching.io

    The New Version of the TgToxic Android Banking Trojan Is Coming Back with More Advanced Techniques and Capabilities Recently we discovered a new version of TgToxic in public Triage, marking its reemergence more than a year after its initial detection. TgToxic was first reported by Trend Micro in early February last year, targeting specific countries. In this latest version we found, based on ...

  • web:thehackernews.com

    TgToxic malware evolves with advanced anti-analysis, DGA-based C2, and global expansion, targeting banking and crypto users

  • web:www.cleafy.com

    Discover Cleafy's in-depth analysis of a new Android banking Trojan campaign, ToxicPanda, initially linked to TgToxic . Our findings reveal a sophisticated fraud operation targeting European and LATAM banks, using On-Device Fraud (ODF) tactics to execute account takeovers. Learn about ToxicPanda's evasion techniques and its early-stage development as it aims to bypass banking security measures.

  • web:www.intel471.com

    Intel 471 mobile malware researchers recently discovered a campaign leveraging an updated version of TgToxic , an Android banking trojan. Here's an in-depth look at this malware .

  • web:www.pcrisk.com

    This malware also steals Google Authenticator 2FA codes through the Android Accessibility Services. In conclusion, by hijacking legitimate applications and stealing credentials, TgToxic can perform small transactions without user involvement or knowledge.

  • web:www.scworld.com

    TgToxic's advanced tactics include obfuscation, payload encryption, and anti-emulation techniques. Despite its sophistication, Google confirmed no known infected apps on Google Play, with Google Play Protect automatically shielding users from detected threats.

  • web:www.trendmicro.com

    We look into an ongoing malware campaign we named TgToxic , targeting Android mobile users in Taiwan, Thailand, and Indonesia since July 2022. The malware steals users' credentials and assets such as cryptocurrency from digital wallets, as well as money from bank and finance apps. Analyzing the automated features of the malware , we found that the threat actor abused legitimate test framework ...

  • web:www.vcindi.com

    Conclusion The continuous evolution of TgToxic underscores the growing sophistication of Android banking malware . By implementing dynamic evasion strategies, including enhanced anti-analysis techniques and flexible C2 communication methods, the threat actors behind TgToxic demonstrate their ability to adapt and refine their tactics.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.