TechNewsReel
Live

ToxicPanda 2.0 Trojan Targets 349 Financial Apps Across 16 Countries

Zimperium zLabs researchers uncover an evolved Android banking Trojan using invisible overlays and ADB automation to bypass security.

TechNewsReel Newsroom · August 20, 2026

Cybersecurity researchers at Zimperium zLabs have identified ToxicPanda 2.0, an evolved Android banking Trojan designed for large-scale financial theft. The malware, also known as TgToxic, represents a significant escalation in capability, shifting from regional campaigns to a mature, global fraud platform.

The Trojan currently targets 349 banking, financial, e-wallet, and cryptocurrency applications across 16 different countries. To harvest sensitive data, the malware employs a transparent overlay mechanism that captures PIN inputs from more than 140 targeted financial apps without the user's knowledge. Beyond data theft, ToxicPanda 2.0 supports 167 remote commands, many of which were unimplemented in previous versions of the malware.

Technical Sophistication

To maintain control and evade detection, the attackers utilize legitimate cloud infrastructure, specifically Amazon AWS-hosted buckets, for the distribution of the malware. Once installed, the Trojan establishes command-and-control (C2) communication via HTTPS, which then transitions into a persistent WebSocket channel for low-latency control.

One of the most aggressive features of the 2.0 version is its use of Android Accessibility Services to automate the Wireless Debugging (ADB) pairing process. By automating this setup, the malware obtains shell-level access to the device, allowing attackers to bypass standard security consent flows. Additionally, the Trojan requests VPN privileges during the payload installation phase specifically to block communications from Google Play and Google Play Services, preventing the system from flagging the malicious activity.

Industry Implications

This transition toward "on-device fraud" marks a dangerous shift in the mobile threat landscape. By combining ADB automation with invisible overlays, the operators can effectively neutralize traditional security warnings and runtime permissions that typically protect users from unauthorized access.

The ability to gain shell-level access allows the attackers to maintain deep persistence on a device. This level of control, paired with the ability to harvest credentials across a vast array of global banking and crypto platforms, enables high-value financial theft that is difficult for standard mobile security software to detect in real-time.

Future Outlook

Security professionals are now monitoring for further iterations of the TgToxic codebase as the attackers refine their automation techniques. While the core infrastructure relies on AWS and WebSockets, the primary concern remains the malware's ability to manipulate Android's own debugging tools to grant itself administrative power. Users are encouraged to review their Accessibility Services permissions and ensure that Wireless Debugging is disabled unless actively required for development.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.