ToxicPanda 2.0 Android banking trojan expands to 350 financial apps across 16 countries

An updated Android banking trojan called ToxicPanda 2.0 is targeting mobile banking users in at least 16 countries with a much larger list of financial apps than before. Zimperium says the new version supports 167 remote commands, targets nearly 350 banking and finance apps instead of 16, abuses Android Wireless Debugging to gain elevated shell access on infected phones, and is being delivered from Amazon AWS-hosted buckets.
Why it matters: This raises the risk for Android users who do banking or crypto activity on their phones, especially in the listed countries. Mobile defenders should watch for abuse of Wireless Debugging and cloud-hosted malware delivery, while users should avoid sideloaded apps and suspicious links.

Sources

ToxicPanda Android malware uses VPN permissions to block Google Play
Bill Toulas 2026.08.23 95% relevant
This article updates the same ToxicPanda 2.0 malware campaign with specific new capabilities: abuse of Android VPN permissions to block Google Play and Play Protect traffic, automated Wireless ADB activation for shell-level access, AWS-hosted distribution, expanded remote-command support, and refined persistence and credential-theft features.
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
Eduard Kovacs 2026.08.22 100% relevant
The article provides the concrete campaign update that ToxicPanda 2.0 greatly expanded its command set, targeted-app list, country scope, and delivery infrastructure.
← Back to all stories