New Android Malware Hijacks Bank Calls for Fraudulent Transfers

A new Android banking malware, dubbed ToxicPanda, has infected over 1,500 devices, primarily in Europe and Latin America, enabling fraudulent money transfers by bypassing bank security measures. Believed to be developed by a Chinese-speaking threat actor, ToxicPanda shares similarities with the TgToxic malware but lacks some of its features, suggesting it's in early development. The malware disguises itself as popular apps and exploits Android's accessibility services to gain control over devices, intercept OTPs, and perform unauthorized transactions. Researchers have accessed its command-and-control panel, indicating ongoing development and potential future threats.
- New Android Banking Malware 'ToxicPanda' Targets Users with Fraudulent Money Transfers The Hacker News
- Android Users—New Malware Hijacks Bank Calls, Reroutes To Attackers Forbes
- Android malware FakeCall intercepts your calls to the bank Malwarebytes Labs
- Updated Android malware can hijack calls you make to your bank Fox News
- All Android users placed on red alert - scary bank bug can empty your account in minutes Express
Reading Insights
0
11
3 min
vs 4 min read
86%
645 → 90 words
Want the full story? Read the original article
Read on The Hacker News