• Home
  • Mobiles
  • Mobiles News
  • Toxianda Banking Trojan Infects Over 1,500 Android Smartphones, Targets 16 Banks: Report

Toxianda Banking Trojan Infects Over 1,500 Android Smartphones, Targets 16 Banks: Report 3a4c14

Threat actors can use ToxicFraud banking trojan to perform on-device fraud (ODF) on a victim's smartphone. 4c625w

Toxianda Banking Trojan Infects Over 1,500 Android Smartphones, Targets 16 Banks: Report

Photo Credit: Pixabay/ @neotam j4d2t

Cleafy's Threat Intelligence team said traditional malware scanners were unable to detect Toxianda

Highlights
  • Toxianda is a recently detected Android banking trojan
  • s are prompted to install the trojan using social engineering
  • The Toxianda trojan can gain access to a 's bank s
ment

Toxianda — a banking trojan that is believed to be in an early stage of development — has been detected by security researchers in Europe and Latin America. It is believed to be derived from another banking trojan detected in 2023, and is used to remotely take over s on compromised phones, allowing attackers to transfer funds while bying security measures aimed at stopping suspicious transactions. Toxianda was reportedly found on over 1,500 devices, while targeting s of 16 banking institutions.

Researchers at Cleafy's Threat Intelligence detected a new Android malware in October that they previously detected as TgToxic, another banking trojan that was actively used in Southeast Asia and was identified by the group last year. The researchers found that the new sample did not contain capabilities from TgToxic, and that the code was not similar to the original trojan.

toxianda disguise apps cleafy toxianda

The Toxianda trojan is disguised as popular applications
Photo Credit: Cleafy

 

As a result, the researchers started to track the newly detected remote access trojan (RAT) as Toxianda and warns that the malware can lead to takeover (ATO) after a victim's device is infected. Cleafy's Threat Intelligence team also says that by opting for manual distribution (sideloading, using social engineering), threat actors (TA) can circumvent a bank's security measures that are used to keep s safe.

In order to access almost all information on a 's device, the malware exploits the accessibility service on Android, allowing it to capture data from all apps. It is also capable of sidestepping two-factor authentication (such as OTPs) by capturing the contents of the screen. 

The creators of the Toxianda malware are Chinese speakers, according to the researchers. Over 1,500 devices were infected with the Toxianda trojan and s from Italy were the most impacted — more than 50 percent of all infected devices. Other impacted locations include Portugal, Spain, , and Peru. Customers of 16 banks were reportedly targeted by the TAs using the Toxianda trojan.

The researchers also point out that current antivirus solutions have failed to detect these threats, which suggests the need for a "proactive, real-time detection system". A botnet of infected devices was also spotted in use in Europe and Latin American countries, which suggests that the Chinese-based TAs are now turning their attention to other markets. 

Comments

For the latest reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Android
David Delima
As a writer on technology with Gadgets 360, David Delima is interested in open-source technology, cybersecurity, consumer privacy, and loves to read and write about how the Internet works. David can be ed via email at [email protected], on Twitter at @DxDavey, and Mastodon at mstdn.social/@delima. More
Vivo Y19s Price, Availability Announced; Comes With 5,500mAh Battery, 50-Megapixel Camera
Assassin's Creed Shadows Will Take 'New Direction' With Modern-Day Story, Says Ubisoft
Facebook Gadgets360 Twitter Share Tweet Snapchat LinkedIn Reddit Comment google-newsGoogle News

ment

Follow Us

ment

© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »