Skip to main content
Aggregate PYMNTS 金融科技 29 Aug 2026 - 16:01

Malware Has a Branding Department and ToxicPanda Is Its Latest Star

RSS 官方收录 · 可信分层展示

关键摘要

ToxicPanda sounds like an energy drink formulated for people who regard sleep as a character flaw.…

  • It’s actually an Android banking Trojan capable of taking over phones,…
  • Its newly discovered sequel, ToxicPanda 2.
  • 0, is bigger, more capable and apparently produced by a franchise that…

摘要引擎:抽取

正文提要

ToxicPanda sounds like an energy drink formulated for people who regard sleep as a character flaw.

It’s actually an Android banking Trojan capable of taking over phones, stealing financial credentials and initiating unauthorized transactions. Its newly discovered sequel, ToxicPanda 2.0, is bigger, more capable and apparently produced by a franchise that believes every villain deserves a marketable name.

The latest version puts a fresh spotlight on one of cybersecurity’s stranger traditions. Malware researchers spend their days dissecting hostile code, tracing criminal infrastructure and trying to protect banks from digital burglary. Then somebody must name the culprit. The results often sound less like a threat database than the guest list for a particularly unruly children’s party.

ToxicPanda 2.0 earned attention after zLabs, the in-house mobile threat research and analytics team at enterprise mobile security company Zimperium, said in an Aug. 19 press release that the Android malware now targets 349 banking, financial, digital wallet and cryptocurrency apps across 16 countries. The Trojan has 167 remote commands, giving criminals control over infected devices.

The original ToxicPanda surfaced in 2024 when researchers at cybersecurity platform Cleafy first mistook it for TgToxic, an existing banking Trojan. Closer inspection found enough differences for the team to begin tracking it as a separate family, according to a Cleafy blog post. Cleafy identified more than 1,500 infected devices and said the malware targeted 16 banks across Europe and Latin America. Researchers also found evidence suggesting its operators spoke Chinese, which helps explain the panda half of the name. The toxic half required little imagination.

So, who gets naming rights?

Usually, the researcher or security company that discovers, analyzes or first publishes information about a malware family gets an early shot. There is no global malware registrar sitting in Geneva with a rubber stamp and a large book of forbidden animal puns. Different companies can discover the same code independently and assign different names.

Microsoft acknowledged the resulting confusion. A malware family’s name can depend on who found it first, how the press describes it and which naming rules a security company follows. The same malicious program can therefore collect aliases faster than a con artist changing hotels.

There is a protocol, or at least an effort at one. Microsoft uses the Computer Antivirus Research Organization, or CARO, naming scheme. The structure identifies the threat type, platform, family and variant. A polished Microsoft detection name might resemble “Trojan:MSIL/Solorigate.BR!dha,” which is precise, searchable and unlikely to become a stuffed animal.

Under Microsoft’s naming system, “Trojan” describes what the software does, “MSIL” identifies the platform, “Solorigate” names the family and “BR” marks the variant. CARO dates to the early 1990s and remains widely used, although Virus Bulletin said vendors apply it with variations.

Then come the names built for headlines. Cybersecurity’s hall of fame includes:

  • Roaming Mantis
    Kaspersky chose the name because the Android malware spread through smartphones moving among Wi-Fi networks. It is an unusually literal insect. The same malware is also called MoqHao and XLoader, demonstrating the alias problem in real time.
  • Olympic Destroyer
    This one attacked systems supporting the 2018 Pyeongchang Winter Olympics, disrupted Wi-Fi and ticket printing and wiped files. The name sounds theatrical because the malware behaved theatrically.
  • Bad Rabbit
    The 2017 ransomware masqueraded as an Adobe Flash installer before encrypting files. Its name suggested a children’s book character with serious behavioral issues.
  • Copybara, BingoMod and Medusa
    All three belong to the modern Android banking-malware menagerie cited in Cleafy’s ToxicPanda research. Copybara deserves special recognition for combining copyright infringement, a capybara and financial theft in seven letters.

The whimsy serves a purpose. Memorable names help researchers, journalists and security teams discuss complicated threats without reciting file hashes over lunch. A vivid label can also push an obscure attack into public view. The risk is that branding gives criminals free publicity or makes serious financial harm sound like an animated adventure.

Still, the naming parade will continue. Somewhere, a researcher is staring at several thousand lines of malicious code and deciding whether the world has just met SneakyWalrus, InvoiceFerret or RansomLlama. Let’s hope the name is the most successful part of its career.

The post Malware Has a Branding Department and ToxicPanda Is Its Latest Star appeared first on PYMNTS.com.

打开官方原文 站点原文页 可信分区 本信源更多 今日简报 分享图 RSS 稍后再看列表