started · updated
ToxicPanda 2.0 malware targets 349 financial apps across 16 countries
The ToxicPanda 2.0 malware has significantly expanded its reach, targeting 349 financial applications across 16 countries. This represents a massive increase from the previous version, which targeted only 16 apps. Documented by Zimperium’s zLabs team, the upgraded trojan utilizes a sophisticated infection chain to steal banking credentials.
The attack begins when the malware poses as a legitimate application and requests VPN permissions through a fake installation screen. Once granted, it uses this access to block Google Play Protect, allowing it to decrypt and install a malicious payload hidden within the app’s asset files.
To gain deeper control, the malware abuses Android’s Accessibility Service to monitor the victim’s screen and interact with data. It also exploits Android’s wireless debugging feature by automating the process of unlocking developer options and capturing pairing codes. This allows the malware to gain shell access to the device without the user’s knowledge or explicit activation of developer mode.