Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 21 sources · 28 days · First seen · Last updated
Android banking malware and automotive threats
Overview
New Android banking trojans have been identified targeting financial and cryptocurrency applications globally. The initial threat, known as ‘Rokarolla’, spreads through unofficial app stores and third-party websites by masquerading as legitimate applications like Chrome and TikTok. It is capable of compromising up to 217 apps to steal login credentials, screen-lock passwords, and SMS verification codes.
Subsequent discoveries revealed more sophisticated variants, including ToxicPanda and Manic. ToxicPanda 2.0 utilizes remote commands and accessibility rights to monitor screens and bypass protections, targeting 349 financial institutions across 16 countries. It can also obtain shell-level access via Android Wireless Debugging. Manic combines banking trojan and spyware capabilities, using overlay techniques to steal PINs and OTP codes. Manic targets 169 applications, including government eID and 2FA authenticators, and uses a unique transparent overlay to intercept PINs on legitimate numeric keypads. It also features a data exfiltration mechanism that can transmit encrypted data to nearby compromised devices via Wi-Fi Direct or Bluetooth if the primary device lacks internet connectivity.
Recent findings also highlight a campaign targeting automotive Android head units from the vendor DoFun. By compromising the legitimate TWCore system application, attackers can deploy the JarService malware through the device’s own update mechanism to facilitate ad fraud, technical data extraction, and the creation of residential proxy botnets. This automotive activity has been linked to the MoYu Group and the BadBox network.
Entities
Kaspersky · ThreatFabric · DoFun · Android · MoYu Group
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 7 SOURCES] The Manic malware can exfiltrate stolen data via nearby infected devices using Wi-Fi Direct or Bluetooth when internet is unavailable. www.schmidtisblog.de · www.tecnobreak.com · www.todoandroid.es · www.punto-informatico.it · dev.to · +2 more
- [● 7 SOURCES] Manic targets 169 applications, including banks, cryptocurrency wallets, and government eID services. www.schmidtisblog.de · www.tecnobreak.com · www.todoandroid.es · www.punto-informatico.it · dev.to · +2 more
- [● 5 SOURCES] Kaspersky discovered the first malware campaign specifically designed to infect automotive Android head units. www.diariodetransporte.com · cyberinsider.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 5 SOURCES] The malware was distributed via compromised firmware updates from the provider DoFun. www.diariodetransporte.com · cyberinsider.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 5 SOURCES] The malicious application, named JarService, was delivered through the legitimate TWCore system application. www.diariodetransporte.com · cyberinsider.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 4 SOURCES] The malware's primary objectives include massive ad fraud and extracting technical information from vehicles. www.diariodetransporte.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 4 SOURCES] The activity is believed to be linked to the MoYu Group and the BadBox network of infected devices. www.diariodetransporte.com · www.diarioestrategia.cl · au.pcmag.com · www.silicon.es
- [● 3 SOURCES] The ToxicPanda 2.0 malware targets 349 banking and financial applications across 16 countries. www.ecranmobile.fr · techmaniacs.gr · cybersecuritynews.com
Timeline
-
22 days ago
[TECHNOLOGY] 21 sourcesAndroid malware targets banking apps and automotive systemsNew Android malware threats, including Manic and ToxicPanda 2.0, are targeting banking apps and cryptocurrency wallets, while a novel campaign has been discovered infecting automotive infotainment systems.
-
about 2 months ago
[TECHNOLOGY] 3 sourcesRokarolla banking Trojan targets Android phones globallyRokarolla, a new Android banking trojan that mimics Chrome and TikTok, can hijack up to 217 banking and crypto apps, stealing credentials and OTPs. Users are urged to use only official app stores and keep their
Sources
au.pcmag.com · borncity.com · chip.de · countryrebel.com · cyber-securite.fr · cyberinsider.com · cybernoz.com · dev.to · diariodetransporte.com · diarioestrategia.cl · ecranmobile.fr · punto-informatico.it · schmidtisblog.de · silicon.es · smartdroid.de · soluzionecomputer.it · techmaniacs.gr · technologyreview.de · tecnobreak.com · todoandroid.es · vosveteit.zoznam.sk
This summary has been updated 2 times: see revision history