Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
3 clusters · 19 sources · 19 days · First seen · Last updated
Android banking malware and hybrid ransomware threats
Overview
Security researchers continue to identify sophisticated Android malware strains designed to target banking applications, personal data, and cryptocurrency wallets.
ToxicPanda 2.0 has demonstrated a massive expansion, targeting 349 financial applications across 16 countries. The malware utilizes a complex infection chain where it poses as a legitimate application to request VPN permissions, subsequently blocking Google Play Protect to install malicious payloads. It abuses Android’s Accessibility Service to monitor screens and automate interactions, and exploits wireless debugging features to gain shell access to devices without user knowledge. Research indicates it is often distributed via Amazon AWS-hosted infrastructure and can deploy phishing overlays to deceive users.
Newer threats linked to Indonesian actors have introduced advanced evasion tactics. The Gigabud banking trojan, attributed to the GoldFactory threat group, has been updated to use a modified version of the Shelter app, known as Vwork, to clone legitimate banking applications into an isolated Android work profile. This allows the malware to circumvent security measures by operating in a profile where user alerts or security scans often fail to detect or correlate with malicious activity. This method has been confirmed in Indonesia—where estimated losses reached approximately $960,939 between February and July 2026—and targets 11 countries, including Brazil, Colombia, Mexico, Egypt, Laos, Morocco, the Philippines, Thailand, and Turkey. Infection typically begins via sideloaded apps disguised as government portals, airlines, or tax offices.
Additionally, the Mantax Otax strain represents a hybrid threat, integrating spyware with ransomware functionality. It performs extensive surveillance, including real-time screen recording and harvesting contact lists, before encrypting files on older Android versions. It utilizes an on-screen chat portal to facilitate real-time ransom negotiations, creating a double-extortion threat. These developments complement the Manic malware strain, which uses mesh networking to exfiltrate data without an active internet connection.
Entities
Android · Zimperium · Amazon AWS · Google Play Protect · Gigabud
Timeline
-
2 days ago
[TECHNOLOGY] 8 sourcesGigabud banking trojan exploits Android work profiles to evade detectionThe Gigabud banking trojan, linked to GoldFactory, uses Android work profiles to clone banking apps and evade fraud detection, targeting users across 11 countries including Indonesia and Brazil.
-
17 days ago
[TECHNOLOGY] 9 sourcesToxicPanda 2.0 Android malware targets hundreds of banking appsThe ToxicPanda 2.0 Android malware targets hundreds of banking and crypto apps by abusing Accessibility Services and VPN permissions to bypass security and facilitate financial fraud.
-
20 days ago
[TECHNOLOGY] 7 sourcesToxicPanda 2.0 malware targets 349 financial apps across 16 countriesThe ToxicPanda 2.0 malware has expanded its reach to 349 financial apps across 16 countries, using Android's Accessibility Service and wireless debugging to steal banking credentials.
Sources
ad-hoc-news.de · bl-portal.com · borncity.com · chip.cz · cybernoz.com · dev.to · futurezone.de · informacija.rs · ipaddisti.it · kurir.rs · malwarebytes.org · moncloa.com · news.drweb.com · pcauthority.com.au · punto-informatico.it · schmidtisblog.de · scworld.com · thefabricexchange.com · zimperium.com
This summary has been updated 3 times: see revision history