Feb. 3, 2023, 11:25 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

We look into an ongoing malware campaign we named TgToxic, targeting Android mobile users in Taiwan, Thailand, and Indonesia since July 2022. The malware steals users’ credentials and assets such as cryptocurrency from digital wallets, as well as money from bank and finance apps. Analyzing the automated features of the malware, we found that the threat actor abused legitimate test framework Easyclick to write a Javascript-based automation script for functions such as clicks and gestures.


Article Link: TgToxic Malware’s Automated …

actor android android users apps asia assets automated automation bank campaign credentials cryptocurrency digital features finance framework functions indonesia javascript july july 2022 malware malware campaign mobile money script southeast asia taiwan targeting test thailand threat threat actor wallets

Red Team Operator

@ JPMorgan Chase & Co. | LONDON, United Kingdom

SOC Analyst

@ Resillion | Bengaluru, India

Director of Cyber Security

@ Revinate | San Francisco Bay Area

Jr. Security Incident Response Analyst

@ Kaseya | Miami, Florida, United States

Infrastructure Vulnerability Consultant - (Cloud Security , CSPM)

@ Blue Yonder | Hyderabad

Product Security Lead

@ Lely | Maassluis, Netherlands