TOXICPANDA 2.0 is a newly discovered Android banking Trojan and remote-access tool capable of taking over devices and stealing banking credentials. It significantly expands its targeting capabilities and employs tactics such as phishing and abusing Android's Accessibility Service to execute on-device fraud. The malware aims to perform actions from the infected device rather than from an external machine, which makes it harder for banks to detect fraudulent activities.
Users are advised to avoid sideloading apps, be cautious with apps that request extensive permissions, and use updated anti-malware solutions like Malwarebytes. If infected, users should take measures such as disabling network connections, removing suspicious apps, and potentially performing a factory reset.