ToxicPanda 2.0 Targets 349 Financial Apps and Abuses Android ADB for Shell-Level Access

The malware now targets 349 banking, financial, e-wallet, and cryptocurrency applications across 16 countries, compared with only 16 banking apps in the previously documented version.

ToxicPanda first emerged as an Android banking threat targeting Europe and Latin America. Earlier research found that several remote commands were unfinished, but the newer version reportedly implements many of these functions and expands the malware’s command set to 167 commands.

Previous analysis also linked ToxicPanda to on-device fraud operations, where attackers remotely operate a victim’s legitimate banking session.

ToxicPanda 2.0 Abuses Android ADB

The updated malware abuses Android Accessibility Services to automate user-interface actions, read screen elements, capture touch input, and deploy phishing overlays.

It reportedly requests VPN privileges through a fake installation screen, blocks Google Play and Google Play Services network communications, then decrypts and installs its concealed payload.

Its most concerning capability is the automated abuse of Android’s Wireless Debugging feature. ToxicPanda 2.0 checks whether Developer Options are enabled and, if necessary, simulates taps on the Build Number field to activate them.

It then opens Developer Options, turns on Wireless Debugging, selects the pairing option, and extracts the six-digit pairing code and dynamic port from the screen.

ToxicPanda 2.0 control panel (Source: zimperium)
ToxicPanda 2.0 control panel (Source: zimperium)

Using the captured details, the malware performs local ADB pairing and obtains Android’s shell user capabilities.

This could let operators execute commands through the ADB daemon, broaden permissions, weaken background restrictions, enable components, and improve persistence without relying solely on normal in-app permission prompts.

After installation, ToxicPanda inventories installed applications and sends package names and icons to its command-and-control server.

When a targeted financial app is opened, operators can deliver a matching HTML phishing overlay designed to imitate its login or transaction interface.

The Trojan also includes a PIN-harvesting workflow for more than 140 banking and cryptocurrency apps. It monitors the foreground app using Accessibility Services and can use transparent overlays to collect touches entered by victims.

Malware communicating through WebSocket to command and control server (Source: zimperium)
Malware communicating through WebSocket to command and control server (Source: zimperium)

Through the replacePinTargets command, operators can remotely replace target package names and keywords, allowing campaigns to adapt without a new malware build.

ToxicPanda 2.0 additionally targets device unlock credentials. It can show a fake Android lock-screen overlay to steal a victim’s PIN, pattern, or password, while deceptive full-screen “system update” pages can obscure malicious actions in the background.

The malware communicates with its C2 through HTTPS followed by a persistent WebSocket channel, enabling real-time command delivery and data exchange.

Earlier ToxicPanda variants similarly used WebSockets and AES encryption in ECB mode for C2 traffic. Newly operational commands help ToxicPanda automate OEM-specific permission and persistence settings.

The catAllViewSwitch capability can identify system permission dialogs, battery-optimization prompts, and vendor-specific auto-start settings, then use Accessibility Services to interact with them, Zimperium said.

Indicators of Compromise

IOC TypeIndicatorDescriptionDetection / Hunting Guidance
Malware familyToxicPanda 2.0Android banking Trojan targeting banking, e-wallet, and cryptocurrency appsFlag apps exhibiting Accessibility abuse, overlay activity, and unauthorized Wireless Debugging automation
Delivery infrastructureAWS-hosted bucketReported hosting method for ToxicPanda 2.0 samplesReview mobile download telemetry and block confirmed malicious bucket

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories