< Back to situation

[REVISION HISTORY]

Android banking malware and hybrid ransomware threats

Updated 3 times since CLSTR started tracking revisions of this situation.

What changed

2026-09-10 01:40 UTC → 2026-09-11 12:51 UTC · added removed

Security researchers continue to identify sophisticated Android malware strains designed to target banking applications, personal data, and cryptocurrency wallets. ToxicPanda 2.0 has demonstrated a massive expansion, targeting 349 financial applications across 16 countries. The malware utilizes a complex infection chain where it poses as a legitimate application to request VPN permissions, subsequently blocking Google Play Protect to install malicious payloads. It abuses Android’s Accessibility Service to monitor screens and automate interactions, and exploits wireless debugging features to gain shell access to devices without user knowledge. Research indicates it is often distributed via Amazon AWS-hosted infrastructure and can deploy phishing overlays to deceive users. Newer threats linked to Indonesian actors have introduced advanced evasion tactics. The Gigabud banking trojan trojan, attributed to the GoldFactory threat group, has been updated to use a modified version of the Vwork app Shelter app, known as Vwork, to clone legitimate banking applications into an isolated Android work profile. This allows the malware to circumvent security measures by operating in a profile where user alerts are not visible. or security scans often fail to detect or correlate with malicious activity. This method has been confirmed in Indonesia—where estimated losses reached approximately $960,939 between February and July 2026—and targets 11 countries, including Brazil, Colombia, Mexico, Egypt, Laos, Morocco, the Philippines, Thailand, and Mexico. Turkey. Infection typically begins via sideloaded apps disguised as government portals, airlines, or tax offices. Additionally, the Mantax Otax strain represents a hybrid threat, integrating spyware with ransomware functionality. It performs extensive surveillance, including real-time screen recording and harvesting contact lists, before encrypting files on older Android versions. It utilizes an on-screen chat portal to facilitate real-time ransom negotiations, creating a double-extortion threat. These developments complement the Manic malware strain, which uses mesh networking to exfiltrate data without an active internet connection.

Versions

  1. 2026-09-11 12:51 UTC Android banking malware and hybrid ransomware threats
  2. 2026-09-10 01:40 UTC Android banking malware and hybrid ransomware threats
  3. 2026-08-27 14:18 UTC Android banking malware threats
  4. 2026-08-26 01:28 UTC Android banking malware threats

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.