Overview
- Zimperium’s zLabs published an analysis that documents ToxicPanda 2.0 as an upgraded Android banking trojan with 349 targeted apps across 16 countries and a 167-command remote-control set.
- The campaign delivers samples from Amazon AWS storage buckets, using a fake installer that requests VPN service permission to block Google Play and hide payload extraction and installation.
- ToxicPanda abuses Accessibility Service to read screen UI and deploy invisible overlays and fake lock screens that capture app logins, touch inputs, and device PINs through a dedicated PIN-harvesting module.
- The malware automates Developer Options and Wireless ADB pairing by scraping the six-digit code from the screen, gaining shell-level ADB access to run high-privilege commands that grant permissions and enforce persistence.
- Defenders are urged to block sideloading on managed devices, monitor enabled Accessibility and developer/wireless-debugging settings, deploy behavior-based mobile threat protection, and use Zimperium’s published IOCs for hunting.