Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Connect apps without AI capabilities

Language learners, this is your sign — Babbel’s Deal Days sale ends tonight

July 25th Oliver Tree Memorial Service Livestream: How to Watch

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » The new TGTOXIC Banking Trojan variant evolves with anti-analytic upgrades
Celebrities

The new TGTOXIC Banking Trojan variant evolves with anti-analytic upgrades

By February 27, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 27, 2025Ravi LakshmananCybercrime / Android

Cybersecurity researchers have discovered an updated version of Android malware called TgToxic (also known as toxicity), indicating that the threat actors behind it are making constant changes in response to public reports.

“The changes seen in the TGTOXIC payload reflect the ongoing surveillance of the actors’ open source intelligence, indicating their commitment to improving security measures and enhancing the malware capabilities that keep researchers at bay,” Intel 471 said in a report released this week.

TGTOXIC was first documented by Trend Micro in early 2023 and described it as a Trojan horse for Crypto Wallets and banks that can steal qualifications and funds from banks and financial apps. It focuses primarily on mobile users in Taiwan, Thailand and Indonesia, and has been detected in the wild since at least July 2022.

Cybersecurity

Then, in November 2024, Italian online fraud prevention company Cleafy detailed an updated variant with a wide range of data collection capabilities, expanding its operational scope, including Italy, Portugal, Hong Kong, Spain and Peru. Malware is rated as the job of Chinese-speaking threat actors.

The latest analysis of Intel 471 shows that malware is distributed via SMS messages or via Dropper APK files via phishing websites. However, the exact delivery mechanism remains unknown.

Notable improvements include improved emulator detection capabilities and an update to the command and control (C2) URL generation mechanism, highlighting the ongoing commitment to analytical efforts.

“Malware conducts a thorough evaluation of the hardware and system capabilities of the device to detect emulation,” Intel 471 says. “Malware examines a set of device properties, including brands, models, manufacturers, and fingerprint values ​​to identify discrepancies typical of emulated systems.”

Another important change is to create a fake profile containing an encrypted string pointing to the actual C2 server, using forums such as the Atlassian Community Developer forum, from a hard-coded C2 domain embedded within the malware configuration.

The TGTOXIC APK is designed to randomly select one of the community forum URLs provided in a configuration that acts as a dead-drop resolver for a C2 domain.

This technique offers several advantages. This makes it easier for threat actors to modify the C2 server by simply pointing the community user profile to the new C2 domain without issuing an update to the malware itself.

“This method greatly extends the operational lifespan of malware samples and maintains functionality as long as the user profiles on these forums remain active,” Intel 471 said.

Cybersecurity

Subsequent iterations of TGTOXIC discovered in December 2024 rely on the Domain Generation Algorithm (DGA) to create a new domain name to use as a C2 server. This allows you to create multiple domain names using DGA, making malware more resilient to confusion efforts and allow you to switch to a new domain even if the attacker is removed.

“TGTOXIC stands out as a highly sophisticated Android Banking Trojan with advanced anti-analytic technology, including obfuscation, payload encryption, and ejection prevention mechanisms that avoid detection by security tools.”

“The use of dynamic command and control (C2) strategies such as domain generation algorithms (DGAs), and their automation capabilities allow users to hijack user interfaces, steal entitlements, and perform fraudulent transactions against fraudulent measurements.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHow Trump Dismissed Project 2025 Shapes His Health Policy | Donald Trump News
Next Article 89% of Enterprise Genai use is not visible to organizations exposing serious security risks, new reports reveal

Related Posts

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Queen Letizia of Madrid Sports Sleeveless Hugo Boss Dress

June 26, 2026

Zendaya & Tom Holland’s ‘Spider-Man’ Press Tour Couple Style

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Connect apps without AI capabilities

Language learners, this is your sign — Babbel’s Deal Days sale ends tonight

July 25th Oliver Tree Memorial Service Livestream: How to Watch

How professional creators avoid content droughts

Trending Posts

July 25th Oliver Tree Memorial Service Livestream: How to Watch

June 27, 2026

Vote for Sombre, Phoebe Bridgers and more

June 26, 2026

Bettina Anderson reveals the designer of her wedding dress

June 26, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.