ToxicPanda is an Android banking trojan, also referred to as TgToxic, used to steal banking and digital-wallet credentials and facilitate account takeover and on-device fraud. Active since at least 2022, it has evolved from targeting a limited set of banking applications to a broader international footprint spanning financial institutions across Europe, Latin America, Africa, and Asia. Reporting has consistently noted Chinese-language elements and assessed the operators as likely Chinese-speaking.
The malware abuses Android Accessibility Services to take control of the user interface, grant itself permissions, intercept one-time passwords from SMS and authenticator applications, and manipulate on-screen content. It uses overlay-based phishing to impersonate legitimate banking and cryptocurrency applications, harvesting usernames, passwords, PINs, pattern codes, seed phrases, and device lock credentials. More recent variants significantly expanded their targeting, including support for large numbers of banking, cryptocurrency, and financial applications and institutions across multiple countries.
ToxicPanda also incorporates remote-access functionality that enables operators to conduct fraudulent transactions directly from the victim device. Updated variants reportedly support extensive command sets, establish command-and-control sessions over HTTPS followed by bidirectional WebSocket communications, and can display fake full-screen system-update content to conceal malicious activity. Persistence and control features include requesting Device Administrator privileges, resisting background-execution limits, monitoring package-management events, and interfering with user attempts to disable accessibility permissions or uninstall the malware.
A notable evolution in newer variants is abuse of legitimate Android platform features for privilege escalation. ToxicPanda can use accessibility-driven automated interaction to enable Developer Options and Wireless Debugging, then leverage Android Debug Bridge access to obtain shell-level execution and bypass normal runtime consent flows. Some variants can also overwrite the local device lock credential with an attacker-defined value, strengthening persistence and post-compromise control.
Recent samples have added anti-emulation checks and domain-generation logic to improve resilience and evade analysis. Delivery has been linked to sideloaded Android application packages distributed through traffic-distribution infrastructure and fake application or update lures, although the precise initial infection vector is not always confirmed. Observed campaigns have heavily targeted European users, especially in the Iberian Peninsula, while earlier and parallel activity also affected Southeast Asia and Latin America. ToxicPanda is best characterized as a mobile banking malware family combining credential theft, session-enabling OTP interception, remote device manipulation, persistence, and fraud-oriented post-exploitation on Android devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ToxicPanda is an Android banking trojan designed to steal banking and digital wallets logins, overlaying pin & pattern codes and perform unauthorized transactions.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
During initial communication with the C2 the app receives a JSON payload containing 39 entries, each corresponding to a banking app with its own custom phishing overlay... Overlay attacks work by loading a WebView on top of the legitimate app that looks very similar to the original one.
By abusing the Android accessibility service, threat actors can steal every UI element on the screen, alongside an overlay-based credential theft mechanism.
During the analysis of the malware, we identified multiple persistence techniques, ensuring it remains active even after attempted removal. The malware first registers a unique broadcast receiver... dynamically registers several Receivers | The malware first registers a unique broadcast receiver... which will re-trigger the malware if it receives the “RestartSensor” broadcast.
By abusing the Android accessibility service, threat actors can steal every UI element on the screen, alongside an overlay-based credential theft mechanism.
During the analysis of the malware, we identified multiple persistence techniques, ensuring it remains active even after attempted removal. The malware first registers a unique broadcast receiver... dynamically registers several Receivers | The malware first registers a unique broadcast receiver... which will re-trigger the malware if it receives the “RestartSensor” broadcast.
The new version also fleshes out some of the previously unimplemented commands, siphons lock screen credentials using a fake overlay, and introduces an automated click-based mechanism to abuse Android Wireless Debugging via Android Debug Bridge (ADB) to facilitate privilege escalation and shell-level access on compromised devices.
The malware relies on anti-emulation, code obfuscation, and encryption to thwart detection and reversing efforts.
the Android malware can display full-screen "system update" overlays to conceal its background actions and deploy an invisible transparent overlay to capture touch and harvest PIN codes.
the Android malware can display full-screen "system update" overlays to conceal its background actions and deploy an invisible transparent overlay to capture touch and harvest PIN codes.
54 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking malware that abuses accessibility services to steal UI data, harvest credentials and PINs via overlays, target banking and cryptocurrency apps, enable Wireless Debugging through ADB for privilege escalation, and maintain persistent background execution via device admin and battery optimization bypasses.
An Android banking trojan variant that steals banking and crypto app credentials, uses malicious HTML overlays for credential theft, abuses Android Accessibility Service to enable wireless debugging, gains shell-level access through ADB, bypasses consent prompts, grants itself broad permissions, and maintains persistence. It also steals device lock credentials via screen overlay attacks.
A banking bot used to target customers of multiple financial institutions in Latin America.
Android banking trojan referenced as targeting Europe; likely aimed at stealing banking credentials and/or facilitating fraudulent transactions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.