< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 21 sources · 28 days · First seen · Last updated

Android banking malware and automotive threats

Overview

New Android banking trojans have been identified targeting financial and cryptocurrency applications globally. The initial threat, known as ‘Rokarolla’, spreads through unofficial app stores and third-party websites by masquerading as legitimate applications like Chrome and TikTok. It is capable of compromising up to 217 apps to steal login credentials, screen-lock passwords, and SMS verification codes.

Subsequent discoveries revealed more sophisticated variants, including ToxicPanda and Manic. ToxicPanda 2.0 utilizes remote commands and accessibility rights to monitor screens and bypass protections, targeting 349 financial institutions across 16 countries. It can also obtain shell-level access via Android Wireless Debugging. Manic combines banking trojan and spyware capabilities, using overlay techniques to steal PINs and OTP codes. Manic targets 169 applications, including government eID and 2FA authenticators, and uses a unique transparent overlay to intercept PINs on legitimate numeric keypads. It also features a data exfiltration mechanism that can transmit encrypted data to nearby compromised devices via Wi-Fi Direct or Bluetooth if the primary device lacks internet connectivity.

Recent findings also highlight a campaign targeting automotive Android head units from the vendor DoFun. By compromising the legitimate TWCore system application, attackers can deploy the JarService malware through the device’s own update mechanism to facilitate ad fraud, technical data extraction, and the creation of residential proxy botnets. This automotive activity has been linked to the MoYu Group and the BadBox network.

Entities

Kaspersky · ThreatFabric · DoFun · Android · MoYu Group

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 22 days ago

    [TECHNOLOGY] 21 sources
    Android malware targets banking apps and automotive systems

    New Android malware threats, including Manic and ToxicPanda 2.0, are targeting banking apps and cryptocurrency wallets, while a novel campaign has been discovered infecting automotive infotainment systems.

  2. about 2 months ago

    [TECHNOLOGY] 3 sources
    Rokarolla banking Trojan targets Android phones globally

    Rokarolla, a new Android banking trojan that mimics Chrome and TikTok, can hijack up to 217 banking and crypto apps, stealing credentials and OTPs. Users are urged to use only official app stores and keep their

Sources

au.pcmag.com · borncity.com · chip.de · countryrebel.com · cyber-securite.fr · cyberinsider.com · cybernoz.com · dev.to · diariodetransporte.com · diarioestrategia.cl · ecranmobile.fr · punto-informatico.it · schmidtisblog.de · silicon.es · smartdroid.de · soluzionecomputer.it · techmaniacs.gr · technologyreview.de · tecnobreak.com · todoandroid.es · vosveteit.zoznam.sk

This summary has been updated 2 times: see revision history