The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile

Zimperium's zLabs team has identified a major update to the ToxicPanda Android banking Trojan, which now features a significantly expanded command set of 167 remote commands and a dramatically broader global targeting scope. While the previous version targeted only 16 banking applications, ToxicPanda 2.0 now supports phishing overlays for 349 financial institutions, e-wallets, and cryptocurrency apps across 16 countries. The malware abuses Android Accessibility Services for remote control and has implemented new capabilities, including an automated process to enable Wireless Debugging (ADB) for privilege escalation to shell-level access, a PIN theft mechanism targeting over 140 applications, and the ability to steal lock screen credentials through overlay attacks. It also uses deceptive "system update" screens to hide malicious activity and delivers samples through Amazon AWS-hosted buckets. The malware communicates via encrypted WebSocket connections to its command-and-control server. Zimperium recommends multi-layered protection against such threats, including behavioral detection, network filtering, and on-device runtime protection to disrupt the infection chain and prevent credential theft. 

https://zimperium.com/blog/the-toxicpanda-never-sleeps-toxicpanda-2.0-prepares-its-next-strike-on-mobile

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

OWASP ASVS 5.0 Released - Key Updates and What You Need to Know

Open-SPDD proposes an open framework for Spec-Driven Development workflows