Researchers reported that ToxicPanda 2.0 has significantly expanded its Android banking trojan capabilities, targeting more than 140 banking and cryptocurrency apps and using overlay attacks against 349 financial institutions in 16 countries. The updated malware is designed to steal credentials and PINs, including device lock credentials, by presenting fraudulent screens over legitimate apps and harvesting sensitive input from victims.
The malware also deepens persistence by abusing Android Accessibility Service to enable wireless debugging, interact with consent prompts, and gain shell-level access through the Android Debug Bridge (ADB) daemon. That combination allows attackers to grant broad permissions and maintain access to compromised devices even after initial infection, prompting defenders to prioritize controls such as blocking sideloading on managed devices, treating accessibility grants as privileged events, and alerting on developer options or wireless debugging being enabled.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Zimperium reported that ToxicPanda 2.0 expanded its targeting from 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications and was observed operating across 16 countries. The updated malware also added 167 remote commands, reflecting a broader escalation from banking fraud toward persistent device compromise.
Zimperium reported that ToxicPanda 2.0 evolved to abuse Android VPN permissions to block Google Play and Play Services communications, interfere with Play Protect workflows, and install payloads before requesting Accessibility access. The updated malware also automates Wireless ADB on Android 11+ to gain shell-level access, bypass runtime consent prompts, and strengthen persistence while expanding overlays and PIN theft targeting.
Zimperium's zLabs team discovered the new ToxicPanda 2.0 Android banking trojan variant and published its research. The report described expanded targeting, PIN theft, overlay-based credential theft, and persistence via abuse of Android accessibility and wireless debugging features.
A current GoldDigger Android banking trojan campaign impersonated airline companies and shopping retailers and caused widespread infections in South Africa and the U.K. The malware abused accessibility permissions to perform on-device banking fraud, including injecting input into banking apps to initiate fraudulent transactions.
The earlier iteration of the ToxicPanda Android banking trojan targeted 16 banking applications, providing the baseline from which the newer variant expanded.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcedarkreading.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceinfosecurity-magazine.com
Open sourcezimperium.com
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.