ToxicPanda 2.0 Targets 349 Financial Apps and Steals Android Lock Credentials
ID: f7d6e334-7008-544b-a91d-86d70e5fa416
STIX ID: report--f7d6e334-7008-544b-a91d-86d70e5fa416
Feed Name: HackRead
ToxicPanda 2.0 is an advanced Android banking trojan that arrives as a dropper requesting VPN and Accessibility permissions to install a hidden payload, block Google Play communications, and display phishing overlays for hundreds of financial, e-wallet, and crypto apps. New capabilities include automated enabling of Wireless Debugging (ADB over Wi‑Fi) to obtain shell-level control, fake lock screens to harvest device unlock credentials, vendor-specific persistence steps, and command-and-control via encrypted WebSockets; attackers have hosted payload files on AWS storage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
