TgToxic is an Android banking trojan first publicly identified in 2022 and associated with financially motivated mobile fraud. It is designed to steal banking credentials, take funds from banking and finance applications, and target cryptocurrency held in digital wallets. The malware has been observed in campaigns aimed initially at Southeast Asian users and later at banks and financial targets in Europe and Latin America, indicating geographic expansion.
TgToxic has been distributed through social-engineering operations using phishing sites, deceptive Android applications masquerading as legitimate services, and fraudulent themes such as government assistance or financial services. Campaigns have also used compromised social media accounts and messaging-based lures to direct victims to install malicious applications and grant sensitive permissions. Once installed, the malware can facilitate on-device fraud and unauthorized account access.
Later TgToxic variants showed rapid operational evolution. One variant used dead-drop resolvers on multiple community forums, storing encrypted configuration data in forum profiles to conceal command-and-control discovery. A subsequent variant replaced this mechanism with a domain generation algorithm to improve resilience against takedowns and disruption. Recent samples also incorporated stronger anti-analysis and anti-emulation checks, including validation of Android hardware and software features, device fingerprint inspection, CPU-architecture checks, and detection of common emulator artifacts. Reporting has also linked a related delivery chain to TiramisuDropper acting as a loader for the final TgToxic payload.
TgToxic is widely tracked as an Android banking trojan, and some reporting has referred to a newer strain as ToxicPanda. The operators are assessed to monitor public reporting and adapt their tooling to improve stealth, survivability, and resistance to analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The abuse of legitimate automation frameworks like Easyclick and Autojs can make it easier to develop sophisticated malware
if victim tries to send a direct message to the threat actor through messaging apps such as WhatsApp or Viber
This new version of the trojan abused 25 community forums to host encrypted malware configurations. The actors created user accounts on these forums and embedded specific encrypted strings within the user profiles, serving as dead drop locations from which malware bots could retrieve the final command-and-control (C2) URL.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan with ongoing anti-analysis upgrades; actors adapt based on public reporting.
Android banking trojan that steals credentials, cryptocurrency from digital wallets, and funds from banking/finance apps. Later variants added anti-emulation checks, dead-drop based C2 discovery via community forum profiles, and then a DGA-based C2 mechanism to improve resilience and evade disruption.
Android-focused malware similar to ToxicPanda, likely with banking trojan and RAT capabilities.
Android malware delivered via fake apps and social-media phishing sites. It tricks victims into installing the app and granting permissions such as Accessibility-related access, after which attackers can automatically control the phone and put legitimate apps and assets on the device at risk.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.