< Back to all clusters
[TECHNOLOGY] · United States · 9 sources

started · updated

ToxicPanda 2.0 Android malware targets hundreds of banking apps

Security researchers have identified an advanced evolution of the Android banking Trojan known as ToxicPanda 2.0. This malware is designed for account takeover and on-device fraud by targeting 349 banking, financial, and cryptocurrency applications across 16 countries.

ToxicPanda 2.0 utilizes several sophisticated techniques to gain control over infected devices. It abuses Android’s Accessibility Service to inspect interfaces and automate interactions, and it can create a local VPN interface to manipulate network traffic. This allows the malware to block communications with Google Play and Google Play Services, effectively bypassing security checks and updates. Furthermore, the malware can automate the use of Wireless Debugging (ADB) to execute commands with elevated privileges.

Research from Zimperium and other security entities indicates that the malware is often distributed via Amazon AWS-hosted infrastructure. In addition to stealing credentials and PINs, the malware can deploy phishing overlays to deceive users. Broader industry trends show a significant rise in mobile banking malware, with threat actors increasingly using AI to develop exploits and localize phishing lures. In Latin America specifically, malware families are being adapted to target local payment systems and banking habits.

Entities

Amazon AWS · Android · Android · Google Play · ThreatFabric · ToxicPanda · Zimperium