ToxicPanda Android Malware Infiltrates 4,500+ Devices to Steal Banking Information

A sophisticated Android banking trojan known as ToxicPanda has rapidly escalated its threat footprint across Europe, infecting over 4,500 devices as of early 2025.

Originally identified in Southeast Asia in 2022, ToxicPanda shifted its focus towards Europe, especially Portugal and Spain, capitalizing on a new wave of targeted campaigns.

The malware’s rapid evolution has been closely tracked by security researchers from Trend Micro, TRACE, Cleafy, and others, revealing a pattern of targeted expansion and ongoing technical innovation.

How ToxicPanda Compromises Devices

ToxicPanda is engineered to steal banking and digital wallet credentials, leveraging advanced overlay attacks that mimic legitimate app screens to deceive users into entering their login details, PINs, and pattern unlocks.

Upon infection typically via malicious APK files distributed through hijacked or attacker-controlled websites the trojan baits users into granting extensive permissions, including accessibility and overlay privileges.

Android Banking Malware
malicious files

This allows the malware not only to capture credentials but also to intercept notifications (such as OTP messages), automate device interactions, and persistently hide itself.

A standout feature in recent campaigns is the use of system overlay permissions and accessibility abuse, granting toxic levels of control to attackers.

The malware can alter UI settings, enable or disable services at will, and resist removal attempts by force-closing critical settings windows if a user tries to deactivate essential permissions or uninstall the malicious app.

The campaign predominantly targets popular Samsung, Xiaomi, and Oppo devices both budget and flagship lines across Portugal and Spain, which collectively account for over 85% of all observed global infections.

To efficiently distribute the malware, the threat actors leverage TAG-1241, a sophisticated traffic distribution system (TDS), enabling increased operational resilience and agility in campaign delivery.

The distribution network uses both attacker-registered and compromised domains, serving up malware disguised as Chrome updates or other legitimate services.

Unique to the latest strains, the malware now evades sandbox analysis using anti-emulation checks that detect virtualized environments, further complicating security analysis.

Technically, ToxicPanda employs a Domain Generation Algorithm (DGA) to establish robust Command and Control (C2) communication, periodically generating and cycling through new domains to reduce takedown risks.

Android Banking Malware
some domains are even indexed in google

Encrypted traffic with the C2 is managed via hardcoded AES and DES keys, with sensitive commands, device info, and stolen data exfiltrated over secure websockets.

Researchers note that in case DGA-generated domains become unavailable, the malware leverages a fallback list encrypted and stored locally, ensuring persistent C2 contact.

During analysis, multiple device persistence mechanisms have been documented. The trojan registers broadcast receivers to automatically relaunch itself if removal is attempted, and the use of device admin privileges makes conventional uninstallation highly challenging without command-line intervention via ADB.

Targeted Overlay Attacks

Centrally, the malware’s overlay system is highly adaptive. Upon connecting to C2 infrastructure, ToxicPanda retrieves custom phishing overlays for dozens of specific banking and wallet apps.

These overlays often indistinguishable from real app login forms are designed to harvest credentials en masse.

Updates to targeted overlays reflect ongoing adaptation to geographic campaigns; for instance, recent overlays specifically target Portuguese banking applications, marking a demographic shift in focus since late 2024.

According to the report, ToxicPanda’s growth speaks to a broader surge in Android banking malware, with Kaspersky reporting a 196% year-on-year increase in such attacks globally.

The malware’s ongoing development, resilience strategies, and apparent link to prior infrastructure in Asia underscore the need for continued vigilance among both users and security professionals.

TRACE and other security experts recommend only installing apps from the official Play Store, strictly monitoring app permissions, and avoiding suspicious accessibility requests to reduce infection risk.

ToxicPanda remains a prime example of how modern Android malware families are blending operational agility with technical sophistication to pursue direct financial theft turning a single victim’s device into a high-value target.

Indicators of Compromise (IOCs)

TypeValue/Description
Malicious Packagecom.example.mysoul
C2 IPs38.54.119.95, 104.21.52.214, 172.67.204.27
C2 Domainsbusketmonmaster, ksicngtw[.]org, d7472ad157[.]lol
DGA Domains 2025 (list)See public threat intel repositories
Sample Malicious Sitescheck-googlle[.]com, update-chronne[.]com, mktgads[.]com, ext.
Persistent Filesdom.txt (DES encrypted fallback C2), zipped language files in APK
Password to ZIPBySoulkey&TryEncoderUnit2024114

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories