logo

ToxicPanda Banking Malware Attacking Banking Users To Steal Logins

ID: faacc0b6-9a53-5fef-9bf6-5f2ccf1a9fba

STIX ID: report--faacc0b6-9a53-5fef-9bf6-5f2ccf1a9fba

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2024-11-05

Date Updated: 2026-04-21

Author: Varshini Senapathi

...
...

**ToxicPanda Banking Malware** — Cleafy observed an active campaign of the ToxicPanda Android banking trojan (evolved from TgToxic) targeting users across Europe and Latin America, infecting ~1,500 devices (majority in Italy) and using accessibility-service abuse, SMS/OTP interception, remote control, and C2 communication (domains: dksu.top, mixcom.one, freebasic.cn) to conduct fraudulent transactions up to €10,000.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.