A new version of the ToxicPanda Android banking trojan is widening the danger for mobile users. The malware can steal banking PINs, imitate trusted screens, and take deeper control of infected phones through a feature intended for developers.
ToxicPanda 2.0 arrives with a far broader set of targets and remote commands than earlier versions. It is delivered through malicious files hosted in Amazon AWS buckets, then uses a fake installation flow to persuade victims to approve sensitive Android permissions.
Researchers at Zimperium identified the updated malware and said it has 167 remote commands. The campaign can target more than 140 banking and cryptocurrency apps for PIN theft, while its fake login overlays now cover 349 financial institutions across 16 countries.
The scale matters because the attack does not rely on one stolen password alone. Once installed, ToxicPanda can monitor apps, collect on-screen information, capture touch input, display deceptive pages, and help attackers keep access to the device. Earlier ToxicPanda activity had already infected more than 4,500 devices, largely in Portugal and Spain.
Zimperium said in a report shared with Cyber Security News (CSN) that the new variant also uses Android Wireless Debugging to obtain shell-level access.
That technique gives criminals a route to run commands and weaken normal Android protections without needing physical access to the phone.
The infection begins with a dropper app that displays a false installation interface and asks for VPN-related permission.
This may let the malware interfere with connections to Google Play and Google Play Services before it decrypts and installs its concealed payload.
Accessibility permissions are central to the operation. They allow ToxicPanda to inspect what appears on screen and interact with the interface, a pattern also seen in Android banking trojan attacks that use fake sign-in windows to capture account details.
After installation, ToxicPanda inventories the applications on the device and sends their package names and icons to its command-and-control server.
When a victim opens a selected financial app, the server can return a matching HTML overlay that resembles the genuine login or payment screen.
The malware can also place a transparent layer over a banking keypad to record the victim’s taps. Its <replacePinTargets> command lets operators update the list of apps and keywords used for PIN collection, allowing campaigns to change targets without issuing a new malicious app.
Its Wireless Debugging abuse is especially concerning. ToxicPanda uses automated screen interactions to enable Developer Options, turn on Wireless Debugging, trigger pairing, and collect the temporary six-digit pairing code. It then pairs with the local ADB service at 127.0.0.1 and gains shell user capabilities.
With shell-level access, the malware can attempt to grant itself permissions, bypass background restrictions, enable components quietly, and improve its persistence on the device. This expands the threat beyond a conventional credential-stealing app.
ToxicPanda can also steal device-unlock PINs, passwords, and patterns using a fake Android lock screen. The overlay is designed to resemble the legitimate screen, turning a routine unlock attempt into another credential collection opportunity.
In some samples, the attackers use a fake full-screen system update to conceal malicious activity. This social-engineering method can keep users occupied while the malware changes settings or waits for sensitive information, echoing tactics described in fake Google Play updates used by other Android banking threats.
The updated command set includes options to request Device Administrator privileges and force-reset the phone’s lock-screen password. Another command can load an attacker-controlled web page in a full-screen WebView, giving criminals another way to present phishing content or misleading prompts.
ToxicPanda also attempts to survive Android power-management controls. It identifies the device manufacturer and uses Accessibility Services to navigate vendor-specific auto-start and battery settings, aiming to prevent the operating system from stopping its background processes.
Similar abuse of accessibility-driven device control has become a recurring feature of modern Android banking malware. Users should avoid installing APK files from unsolicited links or unofficial download pages.
They should treat unexpected requests for Accessibility Service, Device Administrator, VPN, Developer Options, or Wireless Debugging permissions as a warning sign, especially when the requesting app is not clearly trusted.
Organizations should watch for unusual Accessibility activity, automated changes to developer settings, suspicious overlay behavior, and unexpected ADB pairing events.
Removing unrecognized apps promptly and reviewing enabled accessibility services can help limit exposure before criminals can establish persistent control.
Indocators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 127.0.0.1 | Local ADB daemon address used during ToxicPanda’s Wireless Debugging pairing process. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…