Automatically translated.View original post

The ToxicPanda 2.0 malware is issuing an account loot.

The ToxicPanda 2.0 malware is issuing robberies of Android users' accounts.

According to a report by the website Cyber Security News, the detection of the return of ToxicPanda malware in a new version under the name ToxicPanda 2.0 by a research team from Zimperium, a mobile security expert firm, the research team said that the new version of the malware has greatly upgraded its capabilities. The malware has expanded the number of applications that are the target of stealing money and data more than ever. The malware has the ability to steal PIN codes from 140 bank applications and Kerrency scripts, and has the ability to overlay the screen to steal access codes on institutional apps. Up to 349 apps in 16 countries around the world. Not only does this version of the malware support up to 167 Command commands, it can be called very versatile.

The research team reported that this malware epidemic will start by tricking the victim into installing a fake application that will act as a dropper. After it runs, the malware will bounce a screen with an interface similar to the official Android app store, Google Play, to install and request permissions related to the virtual private network (VPN or Virtual Private Network). After the installation, the fake app will immediately request permissions for a disabled user assistance or Accessibility Mode. This permissions will allow the malware to do so. Monitor the target application, secretly store data on the screen, trap printing (Keylogging), stack the screen, and allow hackers to remotely access the victim's machine (Remote Access). In addition, after installation, the malware compiles the list of applications, package names, and icons of those applications back to the control server (C2 or Command and Control) for use in the next step.

Then, when the victim gets a financial application job on the list of malware target applications, the malware contacts the C2 server to request a file to overlay the application screen in HTML file format to trap login data through a fake login page. In addition, the malware can also overlay a transparent screen over the bank application's input screen (Banking Keypad). Not only that, the malware can also use the screen overlay with a fake mobile unlock screen to trap the screen unlock code.

The malware has the ability to use commands to update the list of target applications and search queries (Keywords) used to capture PIN codes flexibly without installing a new malware latent application on the victim's machine. In addition, it also makes use of Accessibility Mode to enable Developer Mode or Developer Options to enable Wireless Debugging that gives malware and hackers the right to access the victim's machine at the highest level, or Shell with a pair of ADB Client matches on the victim's own machine through an IP number 127.0.0.1 called a shortcut. Absolutely complete control of the machine.

# Trending # Lemon 8 Howtoo # lemon 8 diary # Toxicpanda2# freedomhack

9/19 Edited to

... Read moreจากประสบการณ์ใช้งานสมาร์ทโฟน ระบบ Android ที่ต้องรับมือกับความเสี่ยงของมัลแวร์ใหม่ ๆ อย่าง ToxicPanda 2.0 นี้ ถือเป็นภัยที่น่ากังวลจริง ๆ สำหรับผู้ใช้งานทั่วไป เพราะมัลแวร์นี้ไม่ได้แพร่กระจายผ่านช่องทางปกติเท่านั้น แต่ยังซับซ้อนด้วยการหลอกให้ติดตั้งแอปปลอมที่ทำหน้าที่เป็น Dropper เพื่อรันมัลแวร์หลัก ในชีวิตประจำวัน ผมแนะนำว่าควรเลือกดาวน์โหลดแอปพลิเคชันเฉพาะจาก Google Play Store ของจริง และตรวจสอบให้แน่ใจว่าแอปที่ติดตั้งมีรีวิวหรือได้รับความนิยม เพราะมัลแวร์ ToxicPanda มักปลอมอินเทอร์เฟซให้เหมือน Google Play เพื่อหลอกขอสิทธิ์ VPN และ Accessibility Mode ซึ่งเป็นจุดสำคัญที่ทำให้มัลแวร์สามารถดักจับข้อมูลสำคัญ เช่น รหัส PIN และข้อมูลล็อกอินของแอปธนาคาร รวมถึงสามารถซ้อนหน้าจอและเก็บข้อมูลแป้นพิมพ์ได้ ผมเองเคยเจอเหตุการณ์ที่มีแอปหน้าตาคล้ายชื่อดัง แต่พยายามขอสิทธิ์เปิดใช้งาน Accessibility หรือ Remote Access ซึ่งเป็นสัญญาณเตือนว่าคุณไม่ควรให้สิทธินี้โดยไม่รู้ที่มา เพราะมันอาจเปิดช่องโหว่ให้มัลแวร์เข้าควบคุมเครื่องและขโมยข้อมูลเงินในบัญชีได้อย่างรวดเร็ว อีกข้อแนะนำสำคัญคือ การตรวจสอบแอปที่อยู่ในโทรศัพท์ว่า มีแอปที่ไม่รู้จักหรือดาวน์โหลดมานานแล้วไม่มีการใช้งานหรือไม่ รวมถึงการตั้งค่าการแจ้งเตือนและติดตั้งแอปป้องกันไวรัสมือถือที่อัปเดตล่าสุดเพื่อสแกนหาแอปผิดปกติ หรือมัลแวร์ที่ซ่อนตัวอยู่ สุดท้าย อย่าลืมตั้งค่ารหัสล็อกหน้าจอที่มีความซับซ้อน และเปิดใช้งานระบบยืนยันตัวตนสองขั้นตอน (2FA) ในแอปธนาคารหรือบริการแอปอื่น ๆ เพื่อเพิ่มชั้นความปลอดภัย หากรู้สึกว่ามีสิ่งผิดปกติเกิดขึ้นกับโทรศัพท์ เช่น แบตเตอรี่ร้อนผิดปกติ หรือใช้งานช้า ควรรีบตรวจสอบและทำความสะอาดเครื่องทันที มัลแวร์ ToxicPanda 2.0 นี้แสดงให้เห็นว่าภัยคุกคามไซเบอร์บนอุปกรณ์มือถือกำลังพัฒนาอย่างรวดเร็ว การมีความรู้และข้อปฏิบัติเพื่อป้องกันตนเองจึงสำคัญมากต่อการรักษาความปลอดภัยข้อมูลและทรัพย์สินส่วนตัวบนมือถือของเรา