logo

ToxicPanda 2.0 Targets 349 Financial Apps and Steals Android Lock Credentials

ID: f7d6e334-7008-544b-a91d-86d70e5fa416

STIX ID: report--f7d6e334-7008-544b-a91d-86d70e5fa416

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: Waqas

...
...

ToxicPanda 2.0 is an advanced Android banking trojan that arrives as a dropper requesting VPN and Accessibility permissions to install a hidden payload, block Google Play communications, and display phishing overlays for hundreds of financial, e-wallet, and crypto apps. New capabilities include automated enabling of Wireless Debugging (ADB over Wi‑Fi) to obtain shell-level control, fake lock screens to harvest device unlock credentials, vendor-specific persistence steps, and command-and-control via encrypted WebSockets; attackers have hosted payload files on AWS storage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.