Particle.news

ToxicPanda 2.0 Expands to 349 Financial Apps and Leverages Android Features for Shell Access

Researchers warn the malware automates legitimate Android features to harvest credentials, evading Play Protect and hiding payload delivery.

Overview

  • Zimperium’s zLabs published an analysis that documents ToxicPanda 2.0 as an upgraded Android banking trojan with 349 targeted apps across 16 countries and a 167-command remote-control set.
  • The campaign delivers samples from Amazon AWS storage buckets, using a fake installer that requests VPN service permission to block Google Play and hide payload extraction and installation.
  • ToxicPanda abuses Accessibility Service to read screen UI and deploy invisible overlays and fake lock screens that capture app logins, touch inputs, and device PINs through a dedicated PIN-harvesting module.
  • The malware automates Developer Options and Wireless ADB pairing by scraping the six-digit code from the screen, gaining shell-level ADB access to run high-privilege commands that grant permissions and enforce persistence.
  • Defenders are urged to block sideloading on managed devices, monitor enabled Accessibility and developer/wireless-debugging settings, deploy behavior-based mobile threat protection, and use Zimperium’s published IOCs for hunting.