← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

ToxicPanda 2.0 Android Malware Expands Global Banking and Cryptocurrency Targeting

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ToxicPanda 2.0 targets over 140 banking and cryptocurrency apps.
  • The malware uses 167 remote commands and abuses Android accessibility services.
  • New features include lock screen credential siphoning and privilege escalation.
  • Distribution now uses Amazon AWS-hosted buckets for malware delivery.

ToxicPanda 2.0 Enhancements

Cybersecurity researchers have identified an updated version of the Android malware, ToxicPanda (also known as TgToxic), which includes significant enhancements. This new iteration features a set of 167 remote commands and has expanded its global targeting footprint. The malware has been active since at least July 2022.

Expanded Targeting and Capabilities

ToxicPanda 2.0 now targets over 140 banking and cryptocurrency applications for PIN harvesting, a substantial increase from the previous version's 16 targets. It abuses Android's accessibility service to steal UI elements and employs an overlay-based credential theft mechanism against 349 financial institutions across 16 countries. The malware also siphons lock screen credentials using fake overlays and introduces an automated click-based mechanism to exploit Android Wireless Debugging via ADB for privilege escalation and shell-level access.

New Functionalities and Evasion Techniques

The updated malware includes functionalities such as prompting victims to grant Device Administrator privileges and overwriting the device's local lock screen PIN with an attacker-defined value. It can also profile infected devices to determine the OEM vendor and take steps to exempt itself from battery optimization policies, ensuring uninterrupted background execution. ToxicPanda 2.0 establishes a bidirectional WebSocket communication channel with its command-and-control (C2) server to receive commands and exchange data.

Distribution Method Shift

Researchers note a shift in the distribution methods for ToxicPanda 2.0. Samples of the malware are now being delivered through Amazon AWS-hosted buckets, indicating that the attackers are leveraging cloud infrastructure for malware delivery. This change in distribution strategy highlights an evolving approach by threat actors to deploy their malicious software.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 15 stories · Aug 20

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Android banking malware ToxicPanda has been updated to version 2.0, significantly expanding its targeting scope to over 140 banking and cryptocurrency applications globally, up from 16. This new version includes 167 remote commands, improved credential harvesting, and new methods for privilege escalation and evading battery optimization policies, posing an increased threat to Android users.