CybersecurityAugust 23, 2026· via Security Affairs

ToxicPanda 2.0: The banking trojan that’s quietly weaponizing Android’s hidden tools

ToxicPanda 2.0: The banking trojan that’s quietly weaponizing Android’s hidden tools

Image : Security Affairs

The once-Europe-focused ToxicPanda malware has evolved into a global threat. Zimperium’s zLabs team has documented ToxicPanda 2.0, a revamped version that now targets 349 financial apps across 16 countries—up from just 16 in its previous iteration. The upgrade isn’t just in scale but in sophistication, with attackers weaponizing Android’s Wireless Debugging framework to bypass security measures and gain near-total device access.

A Trojan with a new playbook

ToxicPanda 2.0 begins as a dropper, masquerading as a legitimate app and requesting VPN permissions through a fake installation screen. Once granted, the malware quietly disables Google Play Protect and decrypts its real payload hidden within the app’s own files. The payload then abuses Android’s Accessibility Service—normally used by screen readers—to monitor every on-screen interaction and harvest credentials via overlay attacks. What sets this version apart is its aggressive use of the Wireless Debugging framework, a feature most users never enable. The malware automates the entire process: enabling developer options, toggling wireless debugging, and scraping the pairing code from the screen to establish a backdoor without the victim noticing.

From regional nuisance to global player

The trojan’s expansion reflects a broader trend in mobile malware: smaller, region-specific threats are being repurposed into high-volume, multi-country operations. ToxicPanda 2.0’s command set has grown to 167 remote instructions, giving attackers granular control over infected devices. Previous analyses by Cleafy had flagged some commands as unimplemented, but Zimperium’s report confirms they are now fully operational, broadening the malware’s fraud and remote-control capabilities.

Why it matters

ToxicPanda 2.0 demonstrates how attackers are exploiting obscure but powerful Android features to sidestep security safeguards. The shift from targeting a handful of European banks to 349 apps across 16 countries signals a professionalization of mobile crime, where malware is no longer a blunt instrument but a precision tool. For users, this means the risks extend beyond phishing emails and fake apps—it’s the hidden corners of the operating system that now demand scrutiny. For defenders, the challenge is clear: traditional detection methods are struggling to keep pace with malware that leverages legitimate system tools for malicious ends.


Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Security Affairs →

← Back to home