started · updated
Android malware targets banking apps and automotive systems
Cybersecurity researchers have identified several sophisticated Android malware threats targeting financial services and automotive systems.
The Manic malware, identified by ThreatFabric, functions as both a banking trojan and spyware. It targets 169 applications, including banks, cryptocurrency wallets, and government eID services. A notable feature is its ability to exfiltrate data via nearby infected devices using Wi-Fi Direct or Bluetooth when internet access is unavailable. It uses an overlay technique to capture PINs by recording touch coordinates on the legitimate keyboard.
Additionally, Kaspersky has documented a novel campaign targeting automotive Android head units. This malware, linked to the MoYu Group and BadBox network, spreads through compromised firmware updates from the provider DoFun. It uses a legitimate system application, TWCore, to deliver a malicious payload called JarService. The primary objectives of this automotive malware are massive ad fraud and the extraction of technical vehicle information.
Separately, the ToxicPanda 2.0 malware has emerged as a significant threat, targeting 349 banking and financial applications across 16 countries. This updated variant features 167 remote commands and can steal credentials even from the lock screen by exploiting Android Accessibility Services.
Entities
Android · DoFun · Kaspersky · MoYu Group · ThreatFabric · Zimperium
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 7 SOURCES] Manic targets 169 applications, including banks, cryptocurrency wallets, and government eID services. www.schmidtisblog.de · www.tecnobreak.com · www.todoandroid.es · www.punto-informatico.it · dev.to · +2 more
- [● 7 SOURCES] The Manic malware can exfiltrate stolen data via nearby infected devices using Wi-Fi Direct or Bluetooth when internet is unavailable. www.schmidtisblog.de · www.tecnobreak.com · www.todoandroid.es · www.punto-informatico.it · dev.to · +2 more
- [● 4 SOURCES] The malware's primary objectives include massive ad fraud and extracting technical information from vehicles. www.diariodetransporte.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 4 SOURCES] The activity is believed to be linked to the MoYu Group and the BadBox network of infected devices. www.diariodetransporte.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 5 SOURCES] The malware was distributed via compromised firmware updates from the provider DoFun. www.diariodetransporte.com · cyberinsider.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 5 SOURCES] Kaspersky discovered the first malware campaign specifically designed to infect automotive Android head units. www.diariodetransporte.com · cyberinsider.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 5 SOURCES] The malicious application, named JarService, was delivered through the legitimate TWCore system application. www.diariodetransporte.com · cyberinsider.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 3 SOURCES] The ToxicPanda 2.0 malware targets 349 banking and financial applications across 16 countries. www.ecranmobile.fr · techmaniacs.gr · cybersecuritynews.com