TgToxic
Malware⚠️ Overview
TgToxic is an Android-based malware family first publicly documented by Trend Micro in January 2024, categorized as a banking trojan and information stealer that targets cryptocurrency exchange and banking applications. It is attributed to a Vietnamese-speaking threat actor group, leveraging social engineering via Telegram to distribute malicious APKs masquerading as security updates or cracked apps.
🔧 Technical Capabilities
TgToxic employs overlay attacks to steal login credentials from over 50 financial and crypto apps, including Binance, Coinbase, and Trust Wallet, using Android's accessibility service to capture two-factor authentication codes and SMS messages. It communicates with a command-and-control (C2) server via HTTP and WebSocket protocols, exfiltrating stolen data in JSON format. Persistence is achieved by registering as a device administrator and hiding its icon from the app drawer. Evasion techniques include checking for rooted devices, disabling Google Play Protect, and using encrypted strings to obfuscate C2 URLs. The malware also abuses Android’s Notification Listener Service to intercept multi-factor authentication (MFA) codes.
📜 History & Notable Incidents
First detected in July 2023, TgToxic gained attention after a campaign in December 2023 that compromised over 2,800 devices across 17 countries, primarily in Southeast Asia, the Middle East, and the United States. No specific CVEs are associated with TgToxic itself, but it exploits Android device vulnerabilities such as the ability to grant accessibility service access without user knowledge. As of early 2025, no law enforcement actions have been publicly announced, and the malware remains active on Telegram channels.
🔍 Detection Indicators
Known indicators include APK file names such as “Update_Crypto.apk” and “SecurityPatch.apk”, with SHA-256 hashes documented in Trend Micro’s report (e.g., 7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8). Behavioral signatures include requests to C2 domains using patterns like “/api/v1/device” and “/api/v1/sms”, along with User-Agent strings mimicking generic Android browsers. Registry keys are not applicable for Android, but mutex names such as “tg_toxic_lock” have been observed in sandbox analyses.
☠️ Risk & Impact
TgToxic primarily causes financial loss through theft of cryptocurrency wallet credentials and banking logins, with the ability to drain accounts in real time via intercepted MFA codes. The affected sectors include cryptocurrency exchanges and retail banking, with victims in Thailand, Vietnam, and the U.S. reported by Trend Micro. Data exfiltration is immediate and automated, leading to account takeover and potential identity theft.
🛡️ Mitigation
Defensive measures include installing apps only from official Google Play Store, enabling Google Play Protect, and granting no accessibility service permissions to unknown apps. Detection rules for network traffic can flag connections to known TgToxic C2 domains and suspicious HTTP POST requests; Trend Micro provides YARA rules and IOCs in their January 2024 advisory.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.