ToxicPanda 2.0 can take over your Android phone and banking apps
ID: b5e5c53f-d9e7-5240-b689-b3d45d10c1f4
STIX ID: report--b5e5c53f-d9e7-5240-b689-b3d45d10c1f4
Feed Name: Malwarebytes Blog
ToxicPanda 2.0 is an Android banking Trojan and remote-access tool that leverages Accessibility Service abuse, overlays, PIN capture, remote control, and attempted Wireless Debugging automation to enable on-device fraud and account takeover; it is delivered via sideloaded apps (currently using AWS-hosted buckets) and uses a dropper that requests elevated permissions and blocks Google services. The report details impacts (stolen credentials, fraudulent transactions, loss of device access), technical behaviors, recommended prevention (avoid sideloading, scrutinize permission requests, use mobile anti-malware), and remediation steps including Safe Mode, revoking Accessibility and Device Administrator rights, removing suspicious apps, and factory reset if necessary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
