Analysis-Houthi advance in Yemen puts U.S. in a new bind
Yemeni Government Forces Strike Houthi Vessels in Taiz Region
Xi Sits Down With Modi on First Trip to India in Seven Years
Iraq and Iran to Jointly Investigate Drone Launchers on Border
RBI Rejects Tata Sons Plea to Nix Shadow Lender Tag, Reports Say
Bahrain Declines Participation in Iran Meeting Regarding Hormuz Strait
HDFC Bank Submits Names of Two CEO Candidates to RBI
Oil Supply Risks Rise After Saudi Pipeline Attack
Modi Seeks BRICS Unity as Global Tensions Rise
BRICS 2026: Modi Seeks Bigger Role For Global South
BRICS Countries Call for Maximum Restraint in the Middle East
Trump Signals US Wants Distance From Iran War
Iranian President Urges BRICS to Oppose Targeting of Civilian Infrastructure
Dell Technologies (DELL) Stock Reaches Record Peak as Founder Climbs to Third Wealthiest Globally
Markets Defy Logic: Stocks Surge 1% Despite Scorching Inflation Numbers
Rocket Lab (RKLB) Stock Gains Analyst Support Despite 46% Decline
GE Vernova (GEV) Stock: Is the Recent 23% Decline Creating a Strategic Entry Point?
Iraq Fires Maysan Commander After Drone Attacks on Saudi Arabia’s Pipeline
Tesla (TSLA) Semi Truck Expansion: European Launch Confirmed for 2027
Cathie Wood’s ARK Invest Pivots to Meta (META) and Rocket Lab in September Trading Activity
Nvidia (NVDA) Eyes $10B Stake in Anthropic’s Historic $2 Trillion IPO
General Motors to Develop Domestic Battery Supply Chains Amid Political Tensions
Iraqi Parliament Speaker Emphasizes State Control Over Weapons
Can Venezuela Rescue the Oil Market?
Can China’s Icicle woo global shoppers in a luxury downturn?
After the I.P.O., a Billion-Dollar Bill for Employee Paydays
Trump Criticizes Europe on Immigration, Trade, and NATO Cooperation
Iraqi Parliament Speaker Backs Urgent Investigation into Recent Attacks
Mexican Authorities Investigate Suspected Cartel-Linked Crypto Mining Operation
Iraqi Prime Minister Dismisses Police Chief in Maysan Province
Iran President and Abu Dhabi Crown Prince Hold Meeting in New Delhi
Iranian President Calls on BRICS to Address Unilateral Sanctions
HDFC Bank Submits Names of Two Candidates for CEO Role to RBI
China's Xi Urges Peace at BRICS Summit Amid Middle East Tensions
Donald Trump Voices Support for Irish Unification
U.S.-Canada trade war set to hit hard in midterm battleground states
Why a $5,000 Trump dividend check won’t solve your money woes
Nvidia (NVDA) Stock Analysis: CEO Jensen Huang Reaffirms $4 Trillion AI Market Vision
Xi Jinping Urges BRICS Nations to Uphold Historical Justice at Summit
Citi sees Fed delivering "a dovish hike" next week
Revolut Data Breach: Fraudulent Government Email Leads to Bitcoin Record Leak
Robinhood (HOOD) Crypto Trading Surges 61% Monthly But Lags 38% Behind 2025 Figures
Oil and Gas Markets Signal Winter Crisis and Rising Interest Rates
Hyperliquid (HYPE) Surges Past $82: Whale Accumulates $322M as Token Burn Accelerates
Former Anthropic Employees Resign Over AI Safety Failures, Warn of Existential Risks
War In the Middle East Crisis is Making Clothes More Expensive
Leaders Arrive At Bharat Mandapam
Trump Affirms Friendship with Saudi Crown Prince Amid Pipeline Attack Concerns
Bitcoin (BTC) Rallies Past $79K as CPI Data Shows Mixed Inflation Signals
What Many Miss Regarding the US-China Rivalry: New Economy
BRICS agrees to joint declaration in test of unity despite Mideast tensions
Trump says Iran war likely to end after midterms as Yemen fighting escalates
Maharashtra Pilots Asset Tokenization as India Embraces Blockchain for Power Grids and Bonds
Trump says Iran probably responsible for attack on Saudi pipeline
Trump Suggests Iran Likely Behind Saudi Pipeline Attack
Iran Signals Potential Shift in Nuclear Policy
Ethereum (ETH) Breaks Past $2,600 Despite Rate Hike Concerns, Reaches Multi-Month Peak
Ford Issues Recall for U.S. Vehicles Over Fuel Tank Hazard
Christine Lagarde: Europe seen from Normandy
Canadian boycott of US products pushes grocers to adapt, explore new supply sources
Iran Shifts to Offensive Military Strategy, Lawmaker States
BRICS 2026: Leaders Arrive At Bharat Mandapam
Canada seeks $1tn from investors looking for a haven from Donald Trump
News Quiz for September 12, 2026
Huawei Technologies Develops Large Language Model for Tourism Content
BRICS Members Reach Joint Declaration Condemning Unilateral War
Iran President Confirms Supreme Leader Mojtaba Khamenei is Alive
Chart of the Week: the long shadow of quantitative easing
Wall Street Economists Adjust Core PCE Forecasts Following CPI Data
Malware Has a Branding Department and ToxicPanda Is Its Latest Star
ToxicPanda sounds like an energy drink formulated for people who regard sleep as a character flaw.
It’s actually an Android banking Trojan capable of taking over phones, stealing financial credentials and initiating unauthorized transactions. Its newly discovered sequel, ToxicPanda 2.0, is bigger, more capable and apparently produced by a franchise that believes every villain deserves a marketable name.
The latest version puts a fresh spotlight on one of cybersecurity’s stranger traditions. Malware researchers spend their days dissecting hostile code, tracing criminal infrastructure and trying to protect banks from digital burglary. Then somebody must name the culprit. The results often sound less like a threat database than the guest list for a particularly unruly children’s party.
ToxicPanda 2.0 earned attention after zLabs, the in-house mobile threat research and analytics team at enterprise mobile security company Zimperium, said in an Aug. 19 press release that the Android malware now targets 349 banking, financial, digital wallet and cryptocurrency apps across 16 countries. The Trojan has 167 remote commands, giving criminals control over infected devices.
The original ToxicPanda surfaced in 2024 when researchers at cybersecurity platform Cleafy first mistook it for TgToxic, an existing banking Trojan. Closer inspection found enough differences for the team to begin tracking it as a separate family, according to a Cleafy blog post. Cleafy identified more than 1,500 infected devices and said the malware targeted 16 banks across Europe and Latin America. Researchers also found evidence suggesting its operators spoke Chinese, which helps explain the panda half of the name. The toxic half required little imagination.
So, who gets naming rights?
Usually, the researcher or security company that discovers, analyzes or first publishes information about a malware family gets an early shot. There is no global malware registrar sitting in Geneva with a rubber stamp and a large book of forbidden animal puns. Different companies can discover the same code independently and assign different names.
Microsoft acknowledged the resulting confusion. A malware family’s name can depend on who found it first, how the press describes it and which naming rules a security company follows. The same malicious program can therefore collect aliases faster than a con artist changing hotels.
There is a protocol, or at least an effort at one. Microsoft uses the Computer Antivirus Research Organization, or CARO, naming scheme. The structure identifies the threat type, platform, family and variant. A polished Microsoft detection name might resemble “Trojan:MSIL/Solorigate.BR!dha,” which is precise, searchable and unlikely to become a stuffed animal.
Under Microsoft’s naming system, “Trojan” describes what the software does, “MSIL” identifies the platform, “Solorigate” names the family and “BR” marks the variant. CARO dates to the early 1990s and remains widely used, although Virus Bulletin said vendors apply it with variations.
Then come the names built for headlines. Cybersecurity’s hall of fame includes:
- Roaming Mantis
Kaspersky chose the name because the Android malware spread through smartphones moving among Wi-Fi networks. It is an unusually literal insect. The same malware is also called MoqHao and XLoader, demonstrating the alias problem in real time. - Olympic Destroyer
This one attacked systems supporting the 2018 Pyeongchang Winter Olympics, disrupted Wi-Fi and ticket printing and wiped files. The name sounds theatrical because the malware behaved theatrically. - Bad Rabbit
The 2017 ransomware masqueraded as an Adobe Flash installer before encrypting files. Its name suggested a children’s book character with serious behavioral issues. - Copybara, BingoMod and Medusa
All three belong to the modern Android banking-malware menagerie cited in Cleafy’s ToxicPanda research. Copybara deserves special recognition for combining copyright infringement, a capybara and financial theft in seven letters.
The whimsy serves a purpose. Memorable names help researchers, journalists and security teams discuss complicated threats without reciting file hashes over lunch. A vivid label can also push an obscure attack into public view. The risk is that branding gives criminals free publicity or makes serious financial harm sound like an animated adventure.
Still, the naming parade will continue. Somewhere, a researcher is staring at several thousand lines of malicious code and deciding whether the world has just met SneakyWalrus, InvoiceFerret or RansomLlama. Let’s hope the name is the most successful part of its career.
Source: PYMNTS.com