Malware
ToxicPanda
ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024. It shows similarity to the TgToxic campaign, but appears to be a new development rather than a derivative. The threat actors are likely Chinese speakers. ToxicPanda initially made use of hardcoded C2 domains only, but started to incorporate a DGA in late 2024.
MITRE ATT&CK TTPs 8
T1027 T1056.002 T1059 T1078 T1136 T1212 T1497 T1497.001
Obfuscated Files or Information
Defense Evasion
GUI Input Capture
Collection
Command and Scripting Interpreter
Execution
Valid Accounts
Defense Evasion
Create Account
Persistence
Exploitation for Credential Access
Credential Access
Virtualization/Sandbox Evasion
Defense Evasion
System Checks
Defense Evasion