ToxicPanda is an Android banking trojan with remote-control capabilities used for credential theft, account takeover, and on-device financial fraud. It targets banking, financial-service, cryptocurrency, and digital-wallet applications. Campaigns have affected Europe and Latin America, with substantial infections observed in Portugal and Spain. Its operators have been associated with Chinese-language elements in the malware and control infrastructure. ToxicPanda shares similarities with the Android malware TgToxic.
The updated variant, ToxicPanda 2.0, supports 167 remote commands and phishing overlays targeting 349 financial applications across 16 countries. A separate PIN-harvesting mechanism targets approximately 140 banking and cryptocurrency applications. It abuses Android Accessibility Services to inspect screen content, automate interactions, and capture sensitive input. Fraudulent login overlays and transparent touch-capture overlays collect account credentials and PINs, while counterfeit Android lock screens steal device-unlock passwords, PINs, and patterns. The malware can intercept one-time passwords delivered through SMS or authenticator applications, enabling attackers to bypass multifactor authentication. It inventories installed applications and communicates with its command-and-control infrastructure to retrieve matching overlays and targeting updates.
ToxicPanda 2.0 automates enabling Developer Options and Wireless Debugging, extracts the displayed pairing code, and pairs with the device's local Android Debug Bridge service. This provides shell-level access without physical access or an external computer, allowing permission changes, reduced background restrictions, and stronger persistence. It also abuses VPN permissions to block Google Play and Google Play Services communications, hindering protective checks. Fake system-update screens conceal malicious activity, manufacturer-specific settings manipulation helps sustain background execution, and anti-emulation checks impede analysis. Samples have been distributed through Amazon Web Services-hosted storage using a deceptive installation flow that decrypts and installs a concealed payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ToxicPanda is an Android banking trojan designed to steal banking and digital wallets logins, overlaying pin & pattern codes and perform unauthorized transactions.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The variant also introduces a lock-screen overlay designed to capture credentials entered by the victim.
The variant also introduces a lock-screen overlay designed to capture credentials entered by the victim.
ToxicPanda automates that process using Android's Accessibility Services. It can enable Developer Options, turn on Wireless Debugging, extract the temporary ADB pairing code, and complete the pairing process with the device's ADB service
One command, ‘autoBoot,’ identifies the host device manufacturer and launches the corresponding OEM-specific auto-start or power management settings to maintain persistence.
Отдельная команда autoBoot определяет производителя устройства и открывает соответствующие настройки автозапуска и энергопотребления... [чтобы] обходить механизмы Xiaomi, OPPO, Vivo, Samsung и Huawei, которые могут завершать фоновые процессы.
The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services. Control at the network level permits the malware to interfere with various security checks and actions, such as app verifications, updates, Play Protect communication, or legitimate disruptions designed to protect users.
The Trojan also adds more sophisticated techniques for compromising Android devices, including privilege escalation and shell-level access through Android's Wireless Debugging and Android Debug Bridge (ADB)
The variant also introduces a lock-screen overlay designed to capture credentials entered by the victim.
ToxicPanda automates that process using Android's Accessibility Services. It can enable Developer Options, turn on Wireless Debugging, extract the temporary ADB pairing code, and complete the pairing process with the device's ADB service
One command, ‘autoBoot,’ identifies the host device manufacturer and launches the corresponding OEM-specific auto-start or power management settings to maintain persistence.
Отдельная команда autoBoot определяет производителя устройства и открывает соответствующие настройки автозапуска и энергопотребления... [чтобы] обходить механизмы Xiaomi, OPPO, Vivo, Samsung и Huawei, которые могут завершать фоновые процессы.
The malware relies on anti-emulation, code obfuscation, and encryption to thwart detection and reversing efforts.
В некоторых образцах вредоноса ... обнаружили полноэкранные окна, имитирующие системные обновления, которые призваны скрыть вредоносную активность малвари.
The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services. Control at the network level permits the malware to interfere with various security checks and actions, such as app verifications, updates, Play Protect communication, or legitimate disruptions designed to protect users.
Новая версия трояна использует фишинговые оверлеи для атак 349 приложений... Отдельный модуль предназначен для перехвата PIN-кодов... ToxicPanda может подменять экран блокировки Android, перехватывая PIN-коды, графические ключи и пароли.
One notable change in ToxicPanda 2.0 is its distribution infrastructure. Researchers observed samples being delivered through Amazon Web Services hosted buckets
The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services. Control at the network level permits the malware to interfere with various security checks and actions, such as app verifications, updates, Play Protect communication, or legitimate disruptions designed to protect users.
Новая версия трояна использует фишинговые оверлеи для атак 349 приложений... Отдельный модуль предназначен для перехвата PIN-кодов... ToxicPanda может подменять экран блокировки Android, перехватывая PIN-коды, графические ключи и пароли.
ToxicPanda 2.0 connects to its command-and-control (C2) server by sending an initial HTTPS request to establish a bidirectional WebSocket communication channel
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison for abuse of Android wireless debugging; no further ToxicPanda activity is described in this reference.
Mentioned only as a comparison: this Android malware family uses mechanisms similar to RatHat's abuse of device settings and local ADB access. The reference provides no further details about its capabilities or targeting.
Mentioned only as an Android malware family previously observed using a technique similar to RatHat's Accessibility-enabled Developer Options/Wireless Debugging abuse.
Mentioned only as a comparison for an infection route involving deceptive app installation and Accessibility permissions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.