Tag: banking
-
ToxicPanda Banking Trojan Matures into Enterprise Threat
The latest version of the Android malware has new features that expand its global reach and put more than users’ financial applications at risk. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat
-
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to security scanners while serving credential-harvesting banking portals to genuine search users. The campaigns target users of major financial institutions and combine search-engine optimization abuse, recently registered lookalike domains, and referral-aware payload delivery to extend…
-
Fake bank websites play dead to evade security scanners
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111
Tags: banking, botnet, edr, infrastructure, international, linux, malware, ransomware, spyware, windowsSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]…
-
ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions…
-
New Manic Android Malware Uses Offline Networks to Drain Bank Accounts
Manic Android malware steals banking credentials and can relay stolen data through nearby infected phones, complicating traditional device isolation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-manic-android-malware-device-relay-data-theft/
-
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers and implants emerging in late May. Manic has rapidly evolved through July, incorporating stronger anti-analysis protections, in-memory DEX loading, lock-screen phishing, and…
-
New Android banking Trojan ToxicPanda 2.0 expands victim targeting
First seen on scworld.com Jump to article: www.scworld.com/brief/new-android-banking-trojan-toxicpanda-2-0-expands-victim-targeting
-
Grandoreiro banking trojan resurfaces with new campaign targeting Latin America
First seen on scworld.com Jump to article: www.scworld.com/brief/grandoreiro-banking-trojan-resurfaces-with-new-campaign-targeting-latin-america
-
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development…
-
‘Grandoreiro’ Malware Resurfaces With Mexico Campaign
The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/grandoreiro-resurfaces-mexico-campaign
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud First seen on thehackernews.com Jump to…
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with “significant enhancements,” including a set of 167 remote commands and expands its targeting footprint globally.Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications. First…
-
Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
Zimperium lifts the lid on the ToxicPanda 2.0 Android banking Trojan First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/updated-toxicpanda-140-banking/
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…
-
Banks look for fraud signals in customer behavior
Banks are dealing with more fraud in which customers authorize payments after being manipulated by criminals. ThreatMark’s Fraud Readiness Benchmark 2026 describes a banking … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/19/threatmark-banking-fraud-prevention-report/
-
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over…
-
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still…
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
LiteLLM Supply-Chain Attack Technology, Banking and Healthcare the Most Affected
Tags: attack, backdoor, banking, credentials, cybersecurity, data-breach, finance, healthcare, supply-chain, technologyThe SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequences. By compromising a…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to identify employees handling payroll, finance, HR, benefits, invoices, and banking workflows. The activity closely overlaps with Microsoft’s “Payroll Pirates” cluster, tracked as Storm-2755. Researchers also found similarities with activity previously documented by Security Risk Advisors, indicating that…
-
Real emails, hijacked payments: Two H1 2026 attack chains
Gen’s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/
-
Astaroth Banking Trojan Adds WhatsApp Web Spambot to Spread Malware Across Brazil
Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts into automated malware relays, marking a significant evolution of the LATAM e-crime ecosystem. Traditionally propagated via email and archive-based phishing, recent campaigns such as STAC3150 and the “Boto Cor-de-Rosa” operation shifted distribution to WhatsApp…
-
Your Money Was Never the Target. Your Identity Was
Identity Theft, Not Transaction Systems, Now Drives the Biggest Banking Fraud Risks Bank of Baroda’s recent breach shows why core systems unaffected is no longer enough. While transactions remained secure, leaked KYC data can fuel mule accounts, synthetic identity fraud and account takeovers, making customer identity – not banking infrastructure – the real target. First…
-
Lampion Malware Targets Portuguese Users With Multistage Phishing and 750MB RAT Payload
A highly targeted Lampion malware campaign abusing localized phishing lures to compromise users in Portugal. The activity reflects a continued evolution of the Brazilian-origin banking trojan, first documented in 2019, which has consistently focused on Portuguese-speaking victims rather than domestic Brazilian targets. In the latest campaign, attackers leverage convincing financial-themed phishing emails masquerading as routine…
-
Brazilian Banking Trojan Actively Spreading in Portugal
Portuguese businesses operate in the same native language as Brazilian hackers, making those businesses easy targets. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/brazilian-banking-trojan-spreading-portugal
-
Paidwork Data Breach Exposes 23.3 Million Accounts, Banking Data and bcrypt Password Hashes
Gig-economy platform Paidwork has been linked to a significant data breach that affects 23.3 million accounts. This breach, involving an approximately 11GB dataset, was publicly released in July 2026. The incident was added to the Have I Been Pwned (HIBP) breach database on July 19, with the compromise reportedly occurring in March 2026. Paidwork Data…

