#ToxicPanda
Vírus ‘ToxicPanda’ se aproxima do Brasil e já ataca América Latina

www.msn.com/pt-br/notici...
November 5, 2024 at 4:29 PM
Nuevo troyano bancario ToxicPanda ataca a Europa y Latinoamérica
7 noviembre, 2024 Por Daniel Pérez Porras
https://unaaldia.hispasec.com/2024/11/nuevo-troyano-bancario-toxicpanda-ataca-a-europa-y-latinoamerica.html
Nuevo troyano bancario ToxicPanda ataca a Europa y Latinoamérica - Una Al Día
Más de 1.500 dispositivos Android han sido infectados por ToxicPanda, un troyano bancario que permite a los actores maliciosos realizar transacciones bancarias fraudulentas. La mayoría de las infec…
unaaldia.hispasec.com
January 1, 2025 at 11:06 PM
[ICYMI] Uang bisa hilang dalam hitungan menit. Identitas digital bisa dicuri. Anda hampir tidak bisa berbuat apa-apa karena ponsel tidak lagi sepenuhnya milik Anda. https://melekmedia.org/artikel/toxicpanda-2-0-bisa-curi-pin-blokir-antivirus/
September 24, 2026 at 4:01 PM
🚨 💰 Banking trojans expand their reach

Manic adds offline mesh exfiltration; #ToxicPanda 2.0 targets 350 financial apps with 167 commands.

🔗 read more: www.securityweek.com...

#ransomNews #cyberthreats #banking
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.
www.securityweek.com
August 24, 2026 at 11:37 AM
ToxicPanda: rilevata diffusione in Italia del nuovo trojan bancario (AL03/241106/CSIRT-ITA) www.csirt.gov.it/contenuti/to...
CSIRT Italia
www.csirt.gov.it
November 6, 2024 at 9:07 PM
ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones
ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones
A new version of the ToxicPanda Android banking trojan is widening the danger for mobile users. The malware can steal banking PINs, imitate trusted screens, and take deeper control of infected phones through a feature intended for developers. ToxicPanda 2.0 arrives with a far broader set of targets and remote commands than earlier versions. It is delivered through malicious files hosted in Amazon AWS buckets, then uses a fake installation flow to persuade victims to approve sensitive Android permissions. Researchers at Zimperium identified the updated malware and said it has 167 remote commands. The campaign can target more than 140 banking and cryptocurrency apps for PIN theft, while its fake login overlays now cover 349 financial institutions across 16 countries. The scale matters because the attack does not rely on one stolen password alone. Once installed, ToxicPanda can monitor apps, collect on-screen information, capture touch input, display deceptive pages, and help attackers keep access to the device. Earlier ToxicPanda activity had already infected more than 4,500 devices, largely in Portugal and Spain. Zimperium said in a report shared with Cyber Security News (CSN) that the new variant also uses Android Wireless Debugging to obtain shell-level access. That technique gives criminals a route to run commands and weaken normal Android protections without needing physical access to the phone. ToxicPanda Android Malware The infection begins with a dropper app that displays a false installation interface and asks for VPN-related permission. This may let the malware interfere with connections to Google Play and Google Play Services before it decrypts and installs its concealed payload. Dropper requesting VPN permission to the victim before payload installation (Source – Zimperium) Accessibility permissions are central to the operation. They allow ToxicPanda to inspect what appears on screen and interact with the interface, a pattern also seen in  Android banking trojan attacks  that use fake sign-in windows to capture account details. Malware installs the payload and requests Accessibility Service permissions (Source – Zimperium) After installation, ToxicPanda inventories the applications on the device and sends their package names and icons to its command-and-control server. When a victim opens a selected financial app, the server can return a matching HTML overlay that resembles the genuine login or payment screen. The malware can also place a transparent layer over a banking keypad to record the victim’s taps. Its  <replacePinTargets>  command lets operators update the list of apps and keywords used for PIN collection, allowing campaigns to change targets without issuing a new malicious app. Malware overlays on top of the victim’s screen (Source – Zimperium) Its Wireless Debugging abuse is especially concerning. ToxicPanda uses automated screen interactions to enable Developer Options, turn on Wireless Debugging, trigger pairing, and collect the temporary six-digit pairing code. It then pairs with the local ADB service at  127.0.0.1  and gains shell user capabilities. With shell-level access, the malware can attempt to grant itself permissions, bypass background restrictions, enable components quietly, and improve its persistence on the device. This expands the threat beyond a conventional credential-stealing app. Overlays Hide Persistent Control ToxicPanda can also steal device-unlock PINs, passwords, and patterns using a fake Android lock screen. The overlay is designed to resemble the legitimate screen, turning a routine unlock attempt into another credential collection opportunity. In some samples, the attackers use a fake full-screen system update to conceal malicious activity. This social-engineering method can keep users occupied while the malware changes settings or waits for sensitive information, echoing tactics described in  fake Google Play updates  used by other Android banking threats. Malware overlay used to steal password of the victim (Source – Zimperium) The updated command set includes options to request Device Administrator privileges and force-reset the phone’s lock-screen password. Another command can load an attacker-controlled web page in a full-screen WebView, giving criminals another way to present phishing content or misleading prompts. ToxicPanda also attempts to survive Android power-management controls. It identifies the device manufacturer and uses Accessibility Services to navigate vendor-specific auto-start and battery settings, aiming to prevent the operating system from stopping its background processes. Similar abuse of accessibility-driven device control has become a recurring feature of  modern Android banking malware . Users should avoid installing APK files from unsolicited links or unofficial download pages. They should treat unexpected requests for Accessibility Service, Device Administrator, VPN, Developer Options, or Wireless Debugging permissions as a warning sign, especially when the requesting app is not clearly trusted. Organizations should watch for unusual Accessibility activity, automated changes to developer settings, suspicious overlay behavior, and unexpected ADB pairing events. Removing unrecognized apps promptly and reviewing enabled accessibility services can help limit exposure before criminals can establish persistent control. Indocators of compromise (IoCs):- Type Indicator Description IP address 127.0.0.1 Local ADB daemon address used during ToxicPanda’s Wireless Debugging pairing process.  Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones appeared first on Cyber Security News .
cybersecuritynews.com
August 20, 2026 at 2:20 PM
New 'ToxicPanda' Android Malware Hits Users with Fake Money Transfers
t.ly/8I2xy
ToxicPanda Android Malware - Spot
New Android Banking Malware 'ToxicPanda' Targets Users with Fraudulent Money Transfers
t.ly
November 5, 2024 at 5:51 PM
#ThreatIntel #EU - ToxicPanda Android banking trojan seen deployed in 🇵🇹 and 🇪🇸

www.bitsight.com/blog/toxicpa...
ToxicPanda Malware in 2025 | Bitsight TRACE Threat Research
What is ToxicPanda? Bitsight Trace dives into detail on the banking malware, from impact breadth, delivery, technical analysis, and more. Learn more now.
www.bitsight.com
August 2, 2025 at 8:16 AM
ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones

cybersecuritynews.com/toxicpanda-a...

#Cybersecurity #ThreatIntel #Vulnerability
ToxicPanda Android Malware Can Steal Banking PINs and Gain Shell Access to Phones
ToxicPanda 2.0 targets 140+ banking apps, steals PINs, overlays screens, and uses 167 commands to control Android devices.
cybersecuritynews.com
August 20, 2026 at 3:01 PM
Cómo blindarte ante ToxicPanda, el nuevo malware que roba cuentas bancarias en Europa 👇
Cómo blindarte ante ToxicPanda, el nuevo malware que roba cuentas bancarias en Europa
Esto es todo lo que sabemos sobre ToxicPanda, el nuevo software malicioso que está infectando dispositivos en países europeos.
www.adslzone.net
November 14, 2024 at 8:32 PM
August 23, 2026 at 6:17 PM
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

huntaegis.com
August 22, 2026 at 2:04 PM
Der neue Banking-Trojaner ToxicPanda hebelt Google Play aus und übernimmt die Kontrolle über Android-Geräte. Oft hilft nur ein Werksreset. #Android #Datensicherheit
Vorsicht vor ToxicPanda: Dieser Android-Trojaner blockiert Google Play
winfuture.de
August 26, 2026 at 6:12 PM
ToxicPanda 2.0 Trojan Is Here, and It's Hunting 349 Banking Apps Across 16 Countries
www.androidheadlines.com/2026/08/toxi... #trojan #malware #Android
ToxicPanda 2.0 Trojan Is Here, and It's Hunting 349 Banking Apps Across 16 Countries
ToxicPanda 2.0 Trojan is now here, and it's a new and improved version of the initial malware. It can now affect 349 banking apps.
www.androidheadlines.com
August 20, 2026 at 1:36 PM
ToxicPanda Banking Trojan Matures into Enterprise Threat
ToxicPanda Banking Trojan Matures into Enterprise Threat
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
www.darkreading.com
August 24, 2026 at 3:06 PM