bankingtrojan (3)

31244160457?profile=RESIZE_400xThe zLabs team recently identified an updated variant of ToxicPanda, the Android banking Trojan known to have primarily targeted Europe, that introduces significant enhancements, including a comprehensive command set of 167 remote commands and substantially expands its targets globally.  Among the newly added capabilities is a PIN theft mechanism targeting more than 140 banking and cryptocurrency applications. By abusing the Android Accessibility Service, threat actors can steal every UI element

31189739096?profile=RESIZE_400xIn May 2026, FortiGuard Labs identified an attack targeting users in Spain and Portugal involving the banking Trojan Ousaban.  This malware has been active in Brazil and is spread through an MSI downloader.  The malicious payload is a DLL that is loaded via DLL sideloading or process injection.

In this campaign, the threat actor primarily targets users in Spain and Portugal. Figure 1 shows how the attack unfolds.  The phishing PDF tricks victims into visiting a malicious webpage that scans the u

31105252057?profile=RESIZE_400xCyfirma cybersecurity researchers have unveiled a detailed analysis of a new threat: TaxiSpy RAT, a sophisticated Android banking trojan with remote access capabilities.  This malware primarily targets Russian users and financial institutions, compromising apps related to banking, cryptocurrency, government services, and online marketplaces.  The report highlights how this threat exploits vulnerabilities to facilitate financial fraud, posing significant risks to individuals and organizations ali