Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

NCSC Urges Stronger Controls for Agentic AI Systems

August 20, 2026

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud

August 20, 2026

Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps

August 20, 2026
Facebook X (Twitter) Instagram
Thursday, August 20
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps
News

Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps

Team-CWDBy Team-CWDAugust 20, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security researchers have warned of a new variant of a prolific Android banking Trojan which substantially expands its potential victim count.

ToxicPanda 2.0 was discovered by Zimperium’s zLabs team, the mobile security vendor wrote in a post on August 19.

Most notable is a PIN-theft mechanism designed to target 140 banking and cryptocurrency applications, and an overlay-based credential theft mechanism targeting 349 financial institutions.

That’s a big increase on the 16 banking apps the first iteration of the Android malware targeted.

Read more on Android malware: Mirax Android Trojan Turns Devices Into Residential Proxy Nodes

When the victim launches one of the targeted applications, the malware requests the relevant malicious HTML overlay from its C2 server. According to the report, most of the financial institutions across 16 countries are in Pakistan, South Africa, Mexico, Nigeria and India.

One of the new features is its abuse of the Android Accessibility Service that enables wireless debugging. It effectively tries to turn this functionality into a route to shell access.

“Once the malware gains shell user permissions, it starts executing high-privilege commands directly through the ADB [Android Debug Bridge] daemon,” the report noted. “The malware bypasses standard Android runtime consent prompts to grant itself broad permissions, neutralize OS background restrictions, silently enable critical components, and enforce persistence.”

Also new to ToxicPanda 2.0 is the ability to steal device lock credentials via a screen overlay attack, granting an attacker persistent access to a compromised device.

Three Controls to Mitigate ToxicPanda

BeyondTrust deputy CISO, Bradley Smith, suggested three ways for enterprises to mitigate the impact of the Android Trojan.

  • Block sideloading on any device enrolled in corporate identity
  • Treat accessibility service grants as privileged access events, which are subject to logging and review
  • Alert when developer options or wireless debugging switch on across the managed fleet. This is possible via mobile device management (MDM)

“What stands out to me in this research is that ToxicPanda 2.0 does not break Android, it operates Android,” Smith argued.

“We’ve been seeing this pattern across mobile threats all year: abuse of legitimate platform features, accessibility services above all, rather than exploitation of vulnerabilities. There is no patch for a feature working as designed, so the control plane must move from patching to governing who and what gets those grants.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleEnterprise Defenses Recovered at the Edge and Collapsed Inside
Next Article WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud
Team-CWD
  • Website

Related Posts

News

NCSC Urges Stronger Controls for Agentic AI Systems

August 20, 2026
News

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud

August 20, 2026
News

Enterprise Defenses Recovered at the Edge and Collapsed Inside

August 20, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Chronology of a Skype attack

February 5, 2026

In memoriam: David Harley

November 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.