A new variant of the Android banking Trojan, named ToxicPanda 2.0, has been identified, significantly increasing its target range to 140 banking and cryptocurrency apps and an overlay mechanism for 349 financial institutions. Discovered by Zimperium's zLabs, this malware exploits Android's Accessibility Service to gain unauthorized access and enables features like stealing device lock credentials.
To mitigate risks, experts recommend blocking sideloading, treating accessibility service grants as privileged, and monitoring developer options via mobile device management.