w
Feb. 3, 2023, midnight |

Trend Micro Simply Security www.rssmix.com

We look into an ongoing malware campaign we named TgToxic, targeting Android mobile users in Taiwan, Thailand, and Indonesia since July 2022. The malware steals users’ credentials and assets such as cryptocurrency from digital wallets, as well as money from bank and finance apps. Analyzing the automated features of the malware, we found that the threat actor abused legitimate test framework Easyclick to write a Javascript-based automation script for functions such as clicks and gestures.

actor android android users apps asia assets automated automation bank campaign credentials cryptocurrency digital features finance framework functions indonesia javascript july july 2022 malware malware campaign mobile money reports script southeast asia taiwan targeting test thailand threat threat actor trend micro research : articles trend micro research : cyber crime trend micro research : cyber threats trend micro research : malware trend micro research : mobile trend micro research : phishing wallets

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Open-Source Intelligence (OSINT) Policy Analyst (TS/SCI)

@ WWC Global | Reston, Virginia, United States

Security Architect (DevSecOps)

@ EUROPEAN DYNAMICS | Brussels, Brussels, Belgium

Infrastructure Security Architect

@ Ørsted | Kuala Lumpur, MY

Contract Penetration Tester

@ Evolve Security | United States - Remote

Senior Penetration Tester

@ DigitalOcean | Canada