The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile
Zimperium's zLabs team has identified a major update to the ToxicPanda Android banking Trojan, which now features a significantly expanded command set of 167 remote commands and a dramatically broader global targeting scope. While the previous version targeted only 16 banking applications, ToxicPanda 2.0 now supports phishing overlays for 349 financial institutions, e-wallets, and cryptocurrency apps across 16 countries. The malware abuses Android Accessibility Services for remote control and has implemented new capabilities, including an automated process to enable Wireless Debugging (ADB) for privilege escalation to shell-level access, a PIN theft mechanism targeting over 140 applications, and the ability to steal lock screen credentials through overlay attacks. It also uses deceptive "system update" screens to hide malicious activity and delivers samples through Amazon AWS-hosted buckets. The malware communicates via encrypted WebSocket connections to its command-and-control server. Zimperium recommends multi-layered protection against such threats, including behavioral detection, network filtering, and on-device runtime protection to disrupt the infection chain and prevent credential theft.
Comments
Post a Comment