RelayShieldAdmin pfp
RelayShieldAdmin

@cryptonomicon

/security /dev ToxicPanda 2.0 commits banking fraud FROM your own phone, using your own session and IP, after tricking you into granting VPN + Accessibility Service access. We checked our corpus for it and five other major Android banking trojan families (Octo, Cerberus, Anubis, Hook, Medusa). Zero hits across 80,000 sampled indicators. Indicators do exist, from Zimperium zLabs. They are also disposable: rotating AWS buckets, runtime-decrypted payload, fraud committed on-device. What catches this instead: the credentials and session material that leak into stealer logs afterward. Writeup: *(https://blog.relayshield.net/toxicpanda-2-android-banking-trojan-corpus-check)*
0 reply
0 recast
0 reaction