ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
Zimperium documents ToxicPanda 2.0, an Android banking trojan now targeting 349 financial institutions in 16 countries via ADB privilege escalation and overlay credential theft.
Zimperium's zLabs documented ToxicPanda 2.0, an Android banking trojan expanding from 16 targeted apps to 349 financial institutions across 16 countries, with 167 remote commands. It poses as a dropper, abuses VPN permissions to block Google Play Protect while installing a hidden payload, then uses the Accessibility Service for screen monitoring and overlay-based credential theft. It automates enabling Android Wireless Debugging and completes the pairing handshake to gain ADB shell access for privilege escalation, and overlays fake lock screens to steal device PINs. Previously unfinished commands are now operational and samples are served from AWS-hosted storage buckets.
- Expanded from 16 to 349 targeted financial apps across 16 countries with 167 remote commands
- Uses fake VPN permission prompt to block Google Play Protect while installing payload
- Automates Android Wireless Debugging enablement and pairing for shell-level ADB access
- Overlays fake login and lock screens to steal banking and device credentials
- Now distributed from AWS-hosted buckets; earlier unfinished commands are operational
Full article1,077 words · extracted from securityaffairs.com · click to collapse

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials.
ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions across 16 countries, up from 16 apps in the previous version, plus a command set that ballooned to 167 remote instructions.
The infection starts with a fairly standard trick dressed up in a new coat of paint. The malware poses as a dropper, requesting VPN permissions through a fake installation screen, then quietly uses that access to block communication from Google Play Protect while it decrypts and installs the real payload hiding inside the app’s own asset files. Once installed, it leans on Android’s Accessibility Service, the same feature legitimate screen readers and automation tools rely on, to see and interact with everything happening on the victim’s screen.
ToxicPanda was once a malware mainly targeting a small number of European banks. That has changed. Zimperium’s zLabs team has documented ToxicPanda 2.0, which now targets 349 financial institutions in 16 countries, compared with just 16 apps before. It also has 167 different commands that attackers can send remotely.
The attack starts with a common trick. The malware pretends to be a legitimate app and asks for VPN permissions through a fake installation screen. It then uses this access to block Google Play Protect while secretly installing the real malware hidden inside the app’s files.
Once installed, ToxicPanda abuses Android’s Accessibility Service. This feature is normally used by legitimate tools such as screen readers, but the malware uses it to monitor the victim’s screen and interact with apps and data on the device.
“By abusing the Android Accessibility Service, threat actors can steal every UI element on the screen, alongside an overlay-based credential theft mechanism targeting 349 financial institutions, compared to the previous version, which targeted only 16 banking applications, the latest iteration demonstrates a significant expansion in targeting scope and capabilities.” reads the report published by Zimperium’s zLabs. “Several commands previously identified as unimplemented in Cleafy’s analysis are now fully operational, expanding the malware’s remote control and fraud capabilities.”
What sets this version apart isn’t just scale, it’s a genuinely new privilege escalation trick built around a feature most people have never touched: Android’s Wireless Debugging framework. The malware automates the entire process of turning it on, tapping the build number seven times to unlock developer options, toggling wireless debugging, and then scraping the six-digit pairing code straight off the screen using accessibility permissions.
From there it performs the actual cryptographic pairing handshake itself, gaining shell-level access to the device without the victim ever realizing developer mode got switched on.
ToxicPanda was once a malware mainly targeting a small number of European banks. That has changed. Zimperium’s zLabs team has documented ToxicPanda 2.0, which now targets 349 financial institutions in 16 countries, compared with just 16 apps before. It also has 167 different commands that attackers can send remotely.
The attack starts with a common trick. The malware pretends to be a legitimate app and asks for VPN permissions through a fake installation screen. It then uses this access to block Google Play Protect while secretly installing the real malware hidden inside the app’s files.
Once installed, ToxicPanda abuses Android’s Accessibility Service. This feature is normally used by legitimate tools such as screen readers, but the malware uses it to monitor the victim’s screen and interact with apps and data on the device.
The real danger comes from its ability to use Android Debug Bridge (ADB). Once connected, ToxicPanda can run commands through ADB without showing the usual permission requests. This allows it to give itself more permissions, remove Android restrictions on background activity, enable important components without the user knowing, and maintain access to the device.
“The malware also introduces an automated click-based mechanism to abuse Android Wireless Debugging (ADB), enabling privilege escalation and shell-level access on compromised devices. Additionally, it can steal lock screen credentials by placing overlays on top of the lock screen.” continues the report.
The credential theft itself runs on two separate tracks. For banking and crypto apps specifically, the malware watches which app the victim opens, matches it against a list of 349 targets, and either overlays a fake login screen or deploys an invisible transparent layer to capture every touch and PIN entry directly. Separately, it can now overlay a convincing fake version of the phone’s own lock screen to steal the device PIN, pattern, or password outright, which hands attackers a way back in even after the initial infection window closes.
Several capabilities that security firm Cleafy had previously flagged as unfinished in an earlier ToxicPanda variant are now fully working. The malware can automatically click through OEM-specific permission dialogs across Xiaomi, Samsung, Huawei, and other manufacturers’ customized Android builds, request Device Administrator privileges using a fake “system service” prompt, and even remotely force-reset a victim’s lock screen password using legitimate Android device management APIs. It can also load an attacker-controlled webpage inside a full-screen overlay on command, a feature that simply didn’t exist in prior versions.
Distribution has shifted too, with samples now getting served from Amazon AWS-hosted storage buckets rather than whatever ad-hoc infrastructure earlier campaigns used.
“The updated campaign also reveals a shift in distribution methods, with ToxicPanda 2.0 samples being delivered through Amazon AWS-hosted buckets, indicating the attackers are leveraging cloud infrastructure for malware delivery.” states the report.
Using major cloud providers for malware delivery isn’t new, but it does complicate blocking efforts, since flagging an entire AWS IP range as malicious tends to take down a lot of legitimate traffic along with it.
None of this requires a sophisticated zero-day, which is honestly the more unsettling part. Every capability here abuses a feature Android ships intentionally, Accessibility Services, Wireless Debugging, Device Administrator APIs, all designed for legitimate accessibility and enterprise device management.
“As mobile banking threats like ToxicPanda become increasingly sophisticated, conventional signature-based security layers are no longer sufficient to protect enterprise mobile endpoints.” concludes the report.
If you’re responsible for securing mobile endpoints, this is less a “patch something” problem and more a “detect abnormal use of normal features” problem, and that’s a considerably harder thing to build detection around.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, ToxicPanda 2.0)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197681/breaking-news/toxicpanda-2-0-gets-a-major-upgrade.html