A new version of the Android Trojan ToxicPanda threatens users of financial and crypto applications worldwide. The malware undermines security functions and takes almost complete control of the infected smartphones.
The ToxicPanda 2.0 banking Trojan targets 349 financial and crypto applications and attempts to steal digital assets. It is mainly spread via fake apps outside of official stores. Users unknowingly download manipulated browser or dating apps and thus install the Trojan. The Federal Office for Information Security (BSI) classifies the threat as high. A Trojan does not spread independently but requires active installation by the user. Once activated, the program intercepts codes for two-factor authentication.
Like the security company Cimperium reported, the new variant uses 167 different remote commands. A central element of the attack strategy is blocking the Google Play service. By controlling at the network level, the malware prevents important app checks in the background, thereby protecting itself from detection by the operating system’s built-in security mechanisms. Security researchers are particularly critical of the misuse of the Android Debug Bridge (ADB). The troubleshooting interface, which is actually intended for developers, is activated by the malware to enable wireless debugging functions and read the necessary pairing code.
Abuse and protection measureThis gives attackers extensive administrative rights, allows them to execute commands with high privileges and permanently manipulate security settings. In order to remain active on the devices, the program specifically bypasses the energy saving functions of various manufacturers such as Samsung or Xiaomi. The perpetrators use invisible overlays on the screen to record every touch. Sometimes they display fake system updates to disguise ongoing attacks.
The lock screen is also imitated to access access data. Although open operating systems allow software to be installed from any source, this poses significant risks to data security. Users should not carry out installations from unknown sources and should critically question requested permissions for virtual private network (VPN) traffic. It is also advisable to always install system updates promptly.
Research Snipers is currently covering all technology news including Google, Apple, Android, Xiaomi, Huawei, Samsung News, and More. Research Snipers has decade of experience in breaking technology news, covering latest trends in tech news, and recent developments.
Expensive folding cell phones, cameras in headphones and a change in boss: Apple is introducing…
Meta ends a process about addiction design at Facebook with a billion-dollar payment and conditions:…
Mass unemployment, cyberattacks and bioterrorism: Bill Gates paints a bleak picture of artificial intelligence in…
Google is apparently planning a design update for YouTube and YouTube Music on iOS. Discovered…
The hardware manufacturer Commodore and the studio CD Projekt Red are bringing a special C64…
Fans are hoping for an early look at GTA 6 through dubious pre-release versions. Instead…