All incidents

ToxicPanda 2.0 Android banking Trojan targets hundreds of financial apps

malwareopenAug 20, 2026 — Aug 22, 2026
ToxicPanda 2.0 Android banking Trojan targets hundreds of financial apps

ZIMPERIUM’S zLabs has identified a new variant of the Android banking Trojan dubbed ToxicPanda 2.0, which now targets 349 financial applications across sixteen countries. The malware expands far beyond its earlier version that hit just sixteen apps, employing a multi-stage infection chain that begins with a dropper seeking VPN privileges. By masquerading as a legitimate utility, it convinces users to grant access that blocks Google Play Protect and paves the way for the payload to install silently.

Once installed, ToxicPanda 2.0 abuses Android’s Accessibility Service to read screen contents, capture keystrokes and harvest banking credentials entered in legitimate apps. It then creates false overlays that mimic login screens of targeted banks, tricking victims into divulging usernames and passwords. A further privilege-escalation step leverages Wireless Debugging, granting the Trojan deep system access that allows it to hide processes and persist after reboot. The malware also commands cloud-hosted servers to distribute updates and new configurations, ensuring it can adapt quickly to defences.

Zimperium’s analysis notes that no Common Vulnerabilities and Exposures identifiers are linked to the techniques used by ToxicPanda 2.0, relying instead on built-in Android features that are abused rather than exploited. The security firm has not attributed the campaign to any specific threat actor group, though the behaviour matches financially motivated operations seen in other regions. Telemetry shows the Trojan has been active since late August 2026, with fresh samples appearing as recently as 22 August.

Research from Security Affairs and Infosecurity Magazine indicates that ToxicPanda 2.0 currently targets around 140 banking and cryptocurrency programmes while maintaining overlay capabilities for 349 financial institutions worldwide. The Trojan is primarily distributed through sideloaded applications that masquerade as VPN tools or utility apps, tricking users into granting the dangerous permissions it needs. Its use of Accessibility Service and Wireless Debugging reflects a shift towards leveraging legitimate OS functions for malicious ends, making detection harder for conventional antivirus engines.

Enterprises should block installation of apps from unknown sources and enforce a policy that treats any request for Accessibility Service as a privileged action requiring approval. Mobile device management tools ought to monitor developer options and Wireless Debugging flags, alerting when they are enabled on corporate-owned devices. IT teams must also restrict VPN-related permissions to only vetted applications and ensure Google Play Protect remains active and up to date.

Finally, user-training programmes should highlight the risks of granting accessibility or VPN rights to unfamiliar software and encourage reporting of suspicious behaviour.

Security operations centres should integrate mobile threat intelligence feeds that flag Indicators of Compromise related to ToxicPanda 2.0, such as known package names, command-and-control domains and suspicious Accessibility Service usage patterns. Regular reviews of mobile device logs for unexpected VPN connections or overlay window creations can help spot infections early. Organisations that maintain a fleet of Android devices ought to consider deploying a dedicated mobile defence platform that behavioural analysis to catch abuse of legitimate APIs before data is exfiltrated.

Intelligence briefing updated Aug 22, 2026

Root sourcezimperium.com
Timeline Coverage

Swipe to explore timeline