Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The variant also introduces a lock-screen overlay designed to capture credentials entered by the victim.
ToxicPanda 2.0 leverages the Android Accessibility Service to enable wireless debugging, effectively gaining shell access and bypassing standard runtime consent prompts.
The Trojan also adds more sophisticated techniques for compromising Android devices, including privilege escalation and shell-level access through Android's Wireless Debugging and Android Debug Bridge (ADB)
The variant also introduces a lock-screen overlay designed to capture credentials entered by the victim.
ToxicPanda 2.0 leverages the Android Accessibility Service to enable wireless debugging, effectively gaining shell access and bypassing standard runtime consent prompts.
ToxicPanda automates that process using Android's Accessibility Services. It can enable Developer Options, turn on Wireless Debugging, extract the temporary ADB pairing code, and complete the pairing process with the device's ADB service
This allows it to execute high-privilege commands, neutralize background restrictions, and enforce persistence.
The malware automates the entire process of turning it on, tapping the build number seven times to unlock developer options, toggling wireless debugging, and then scraping the six-digit pairing code straight off the screen using accessibility permissions. From there it performs the actual cryptographic pairing handshake itself, gaining shell-level access to the device
The variant also introduces a lock-screen overlay designed to capture credentials entered by the victim.
The variant also introduces a lock-screen overlay designed to capture credentials entered by the victim.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Updated Android banking trojan variant targeting financial institutions across 16 countries. It supports 167 remote commands, targets nearly 350 financial apps, and uses an automated click-based mechanism to abuse Android Wireless Debugging (ADB) for privilege escalation and shell-level access.
An Android banking trojan that targets banking and cryptocurrency applications using PIN theft and overlay-based credential theft. It abuses Android Accessibility Service to enable wireless debugging, gain shell access, bypass runtime consent prompts, execute high-privilege commands, maintain persistence, and steal device lock credentials via screen overlay attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.