ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
ID: d8c737eb-234e-5201-a253-37165de4e7d1
STIX ID: report--d8c737eb-234e-5201-a253-37165de4e7d1
Feed Name: Security Affairs
ToxicPanda 2.0 is an upgraded Android banking trojan now targeting 349 financial institutions across 16 countries; it lures victims with a fake installer, disables Play Protect, installs a hidden payload, abuses Android Accessibility Service and automates Wireless Debugging (ADB) pairing to gain shell-level access, deploys overlays and transparent layers to capture banking credentials and device lock PINs, bypasses OEM permission dialogs, and delivers samples from Amazon AWS buckets — representing a scalable, high-impact mobile banking fraud campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
