ToxicPanda 2.0 Android Banking Trojan: New Threat Expands Victim Targeting

www.news4hackers.com-toxicpanda-2-0-android-banking-trojan-new-threat-expands-victim-targeting-toxicpanda-2-0-android-banking-trojan-new-threat-expands-victim-targeting

A newly identified variant of the Android banking Trojan known as ToxicPanda 2.0 has been uncovered by cybersecurity researchers, marking a significant escalation in its scope of operations.

New Android banking Trojan ToxicPanda 2.0 expands victim targeting

The malware now targets 140 banking and cryptocurrency applications through a PIN-theft mechanism, while also leveraging an overlay-based credential theft approach against 349 financial institutions. This represents a substantial expansion from its earlier version, according to reports from Infosecurity Magazine.

The malware was detected by Zimperium’s zLabs team and employs the Android Accessibility Service to enable wireless debugging capabilities. This allows attackers to gain shell access and bypass standard runtime consent prompts, enabling the execution of high-privilege commands. The technique also neutralizes background restrictions and ensures persistent presence on infected devices.

A newly introduced feature facilitates the extraction of device lock credentials via screen overlay attacks, providing adversaries with continuous access to compromised systems. The primary targets of the malware are financial institutions based in Pakistan, South Africa, Mexico, Nigeria, and India. Security experts advise organizations to mitigate risks by enforcing policies that block sideloading on corporate devices and treating grants of accessibility service permissions as high-risk privileges. The malware’s evolution highlights the growing sophistication of mobile banking threats, emphasizing the need for enhanced detection mechanisms and user awareness.

New malware campaign combines social engineering with defense evasion

A recent cyberattack campaign observed in late July 2026 employs compromised WordPress websites to distribute obfuscated ErrTraffic JavaScript. The malicious payload is designed to exploit user trust through social engineering tactics while evading traditional security defenses.

Grandoreiro banking trojan resurfaces with new campaign targeting Latin America

A resurgence of the Grandoreiro banking trojan has been noted in May 2026, with attackers utilizing DLL sideloading techniques to deploy the malware. The campaign specifically focuses on Latin American regions, leveraging compromised systems to steal financial data.


Blog Image

About Author

en_USEnglish