Android Botnet 'ToxicPanda' Bashes Banks Across Europe, Latin America
ID: f31864ef-f072-50fb-badf-8dff20f1cebf
STIX ID: report--f31864ef-f072-50fb-badf-8dff20f1cebf
Feed Name: Dark Reading
Date Published: 2024-11-05
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Researchers have identified ToxicPanda, a new Android banking trojan attributed to Chinese-speaking actors that has infected roughly 1,500 devices across Italy, Portugal, Spain, and Latin America and targets at least 16 financial institutions. ToxicPanda abuses Android accessibility services, captures OTPs (including from authenticator apps), enables remote control to perform fraudulent money transfers while bypassing multifactor protections, and includes code-hiding techniques; the report also highlights Google patches for two actively exploited Android flaws (CVE-2024-43047 and CVE-2024-43093).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
