logo

Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps

ID: f9ebc618-6528-539d-a295-d5787ec62203

STIX ID: report--f9ebc618-6528-539d-a295-d5787ec62203

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

...
...

Security researchers (zLabs) discovered ToxicPanda 2.0, a new Android banking trojan variant that greatly broadens its target set—adding PIN-theft for 140 banking/crypto apps and overlay-based credential theft for 349 financial institutions across multiple countries—and introduces advanced TTPs such as abusing the Android Accessibility Service to enable wireless debugging and ADB shell access, overlay attacks to steal lock-screen credentials, and persistence tactics; the report also recommends enterprise mitigations like blocking sideloading, treating accessibility grants as privileged events, and alerting on developer options/wireless debugging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.