ToxicPanda is an Android banking trojan associated with activity targeting users in Europe. It is tracked under the aliases toxicpanda and toxic_panda. The malware is used to compromise mobile devices for financially motivated fraud, with a focus on banking-related abuse. Based on the available reporting, ToxicPanda is linked to China and is characterized as a mobile threat actor or malware operation rather than a ransomware group or state espionage cluster. High-confidence details beyond its Android banking-trojan role, European targeting, and China-linked origin are currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.