< Back to all clusters
[TECHNOLOGY] · Germany, Spain, France, Italy, Slovakia · 21 sources

started · updated

Android malware targets banking apps and automotive systems

Cybersecurity researchers have identified several sophisticated Android malware threats targeting financial services and automotive systems.

The Manic malware, identified by ThreatFabric, functions as both a banking trojan and spyware. It targets 169 applications, including banks, cryptocurrency wallets, and government eID services. A notable feature is its ability to exfiltrate data via nearby infected devices using Wi-Fi Direct or Bluetooth when internet access is unavailable. It uses an overlay technique to capture PINs by recording touch coordinates on the legitimate keyboard.

Additionally, Kaspersky has documented a novel campaign targeting automotive Android head units. This malware, linked to the MoYu Group and BadBox network, spreads through compromised firmware updates from the provider DoFun. It uses a legitimate system application, TWCore, to deliver a malicious payload called JarService. The primary objectives of this automotive malware are massive ad fraud and the extraction of technical vehicle information.

Separately, the ToxicPanda 2.0 malware has emerged as a significant threat, targeting 349 banking and financial applications across 16 countries. This updated variant features 167 remote commands and can steal credentials even from the lock screen by exploiting Android Accessibility Services.

Entities

Android · DoFun · Kaspersky · MoYu Group · ThreatFabric · Zimperium

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

22 days ago