Malware
TgToxic
According to Trend Micro, TgToxic has been used in an ongoing campaign that has been targeting Android users in Southeast Asia since July 2022.
TgToxic is a Android malware family.
Background
Trend Micro reports that TgToxic features in a continuing campaign that has gone after Android users across Southeast Asia since July 2022. The operation aims to drain victims' funds from finance and banking apps, including cryptocurrency wallets, official mobile banking credentials, and deposited money, using a banking trojan, named TgToxic after its distinctive encrypted filename, hidden inside several counterfeit apps. Having initially focused on Taiwanese users, the campaign's fraudulent activity and phishing lures had, at the time of writing, expanded to victims in Thailand and Indonesia. People are urged to be cautious with embedded links in messages or emails from unknown senders and to steer clear of installing apps from third-party stores.
Source: Malpedia (Fraunhofer FKIE).