[REVISION HISTORY]
Android banking malware and automotive threats
Updated 2 times since CLSTR started tracking revisions of this situation.
What changed
2026-08-21 14:52 UTC → 2026-08-21 21:43 UTC ·
added
removed
New Android banking trojans have been identified targeting financial and cryptocurrency applications globally. The initial threat, known as ‘Rokarolla’, spreads through unofficial app stores and third-party websites by masquerading as legitimate applications like Chrome and TikTok. It is capable of compromising up to 217 apps to steal login credentials, screen-lock passwords, and SMS verification codes. Subsequent discoveries revealed more sophisticated variants, including ToxicPanda and Manic. ToxicPanda 2.0 utilizes remote commands and accessibility rights to monitor screens and bypass protections, targeting 349 financial institutions across 16 countries. It can also obtain shell-level access via Android Wireless Debugging. Manic combines banking trojan and spyware capabilities, using overlay techniques to steal PINs and OTP codes. Manic targets 169 applications, including government eID and 2FA authenticators, and uses a unique transparent overlay to intercept PINs on legitimate numeric keypads. It also features a data exfiltration mechanism that can transmit encrypted data to nearby compromised devices via Wi-Fi Direct or Bluetooth if the primary device lacks internet connectivity. Recent findings also highlight a campaign targeting automotive Android head units from the vendor DoFun. By compromising the legitimate TWCore system application, attackers can deploy the JarService malware through the device’s own update mechanism to facilitate ad fraud, technical data extraction, and the creation of residential proxy botnets. This automotive activity has been linked to the MoYu Group and the BadBox network.
Versions
- 2026-08-21 21:43 UTC Android banking malware and automotive threats
- 2026-08-21 14:52 UTC Android banking malware and automotive threats
- 2026-08-20 17:28 UTC Android banking malware threats
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.