SecurityWorldMarket

Zimperium research uncovers powerful android banking trojan

Dallas, Tx

Zimperium, a global leader in AI-empowered mobile security, has uncovered new research through its Zlabs threat research team detailing the evolution of Toxicpanda 2.0, an advanced Android banking trojan that significantly expands both its technical capabilities and the scale of its fraud campaign.

The latest variant represents a new generation of the original Toxicpanda banking Trojan and introduces 167 remote commands, expanding credential theft from a handful of banking applications to 349 banking, financial, e-wallet, and cryptocurrency applications across 16 countries, and adding sophisticated techniques to compromise Android devices, harvest banking credentials, and maintain long-term persistence on infected devices.

As mobile app adoption continues to rapidly grow for use in banking services, enterprise applications, digital identities, and sensitive corporate data, increasingly sophisticated Android malware poses ever greater risks to both consumers and corporations.

"Toxicpanda 2.0 demonstrates how quickly mobile malware continues to evolve," said Nico Chiaraviglio, Chief Scientist at Zimperium Zlabs. "Rather than simply stealing credentials, this malware automates device compromise, expands financial targeting on a global scale, and abuses legitimate Android features to gain control over infected devices. It reflects the increasing sophistication of modern mobile threats."

Zimperium's AI-empowered, on-device mobile security protects organisations against advanced threats like Toxicpanda by detecting malware, device compromise, phishing overlays, and malicious application behavior before attackers can steal credentials or gain control of the device.


Tags
Back to top