Urgent.News

What's breaking now, across thousands of outlets.

Tech

Malware Has a Branding Department and ToxicPanda Is Its Latest Star

ToxicPanda sounds like an energy drink formulated for people who regard sleep as a character flaw. It’s actually an Android banking Trojan capable of taking over phones, stealing financial credentials and initiating unauthorized transactions. Its newly discovered sequel, ToxicPanda 2.0, is bigger, more capable and apparently produced by a franchise that believes every villain deserves […] The…

Malware Has a Branding Department and ToxicPanda Is Its Latest Star

ToxicPanda, a malicious Android banking Trojan, has gained notoriety for its sophisticated capabilities and recent updates. The latest version, ToxicPanda 2.0, is reportedly more advanced and targets 349 banking, financial, digital wallet and cryptocurrency apps across 16 countries. The Trojan has 167 remote commands, providing criminals with extensive control over infected devices.

Initially discovered in 2024 as a variant of TgToxic, researchers from cybersecurity platform Cleafy identified ToxicPanda as a separate family with over 1,500 infected devices, primarily in Europe and Latin America. The name ToxicPanda is believed to have been inspired by the Chinese-speaking operators behind the malware. Naming malware is a contentious practice, with no global registrar to oversee the process.

Instead, researchers and security companies discover and name malware independently, leading to a proliferation of aliases. Microsoft, for instance, utilizes the CARO naming scheme, which assigns a precise and searchable label to each threat. Despite the potential for confusion, memorable names aid researchers, journalists, and security teams in discussing complex threats.

However, the branding of malware can also inadvertently provide criminals with publicity and trivialize serious financial harm. As researchers continue to dissect malicious code and assign names, the challenge remains to balance the need for clear identification with the potential consequences of sensationalized headlines.

Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pymnts.com →

More in Tech

Structuring Variables in Figma

Building a scalable UI library in Figma starts with thoughtful organization of variables. As projects grow, managing primitives, semantics, and themes without proper structure can quickly become…

Form-Associated Custom Elements: Web Components That Belong in a Form

Custom elements have been shippable for years, but the illusion falls apart the moment you drop one inside a <form> . The value never shows up in FormData . required does nothing.

  • Two lines of code required: set formAssociated to true and call attachInternals().
  • Provide free lifecycle callbacks and validation handling through setValidity() method.

More from Saturday 29 August →