ToxicPanda 2.0 Can Spy on Banking Apps, Fake Lock Screens and Bypass Android Defenses

Lorem Ipsum is simply dummy text of the printing and typesetting industry. Lorem Ipsum has been the industry’s standard dummy text ever since the 1500s, when an unknown printer took a galley of type and scrambled it to make a type specimen book. It has survived not only five centuries, but also the leap into electronic typesetting, remaining essentially unchanged.

It was popularised in the 1960s with the release of Letraset sheets containing Lorem Ipsum passages, and more recently with desktop publishing software like Aldus PageMaker including versions of Lorem Ipsum.

Table of Content

ToxicPanda 2.0 has expanded into a sophisticated Android banking threat capable of targeting financial apps, harvesting PINs and bypassing key security controls.

A new version of the ToxicPanda Android malware has significantly expanded its capabilities, targeting 349 banking, financial, cryptocurrency and e-wallet applications across 16 countries while adding tools designed to steal device PINs and maintain persistent access.

Mobile security company Zimperium detailed ToxicPanda 2.0 in an analysis that describes the malware as a broader attack platform capable of using invisible overlays, fake system screens, Accessibility Services and Android Debug Bridge (ADB) functionality.

The malware can reportedly block communications with Google Play and Google Play Services after obtaining VPN service permissions. This can interfere with Google Play Protect, Android’s built-in malware detection system, before the malicious payload is fully deployed.

ToxicPanda 2.0 then seeks Accessibility Service permissions, which can allow it to observe screen content and interact with other applications. Its overlay system is configured for 349 financial applications, while a separate PIN-harvesting module targets 140 financial and cryptocurrency apps and can dynamically update its target list.

The malware also attempts to capture device credentials by presenting a fake Android lock screen. Users may enter their PIN, pattern or password without realizing that the information is being collected. Fake system update screens can similarly conceal malicious activity while components are installed.

Another major development is ToxicPanda’s abuse of wireless ADB. According to Zimperium, the malware can use Accessibility Services to enable Developer Options and Wireless Debugging, retrieve an ADB pairing code and port, and connect to the device’s local ADB service.

Once connected, it can obtain shell-level access and use that position to grant permissions, modify background-process restrictions and enable additional components.

The malware also includes an autoBoot command that identifies a device manufacturer and navigates to OEM-specific settings intended to keep the malware running in the background. Zimperium said this capability accounts for differences in power-management systems used by manufacturers including Xiaomi, OPPO, Vivo, Samsung and Huawei.

Zimperium has published indicators of compromise for security professionals. For Android users, the company’s findings underscore the importance of installing applications only from trusted sources, carefully reviewing VPN and Accessibility Service requests, keeping Play Protect enabled and checking whether Wireless Debugging is active without authorization.

Users should also monitor financial accounts for suspicious activity and use biometric authentication where available. If an Android device unexpectedly requests unusual permissions or displays suspicious system screens, users should treat the behavior as a potential security warning.

About The Author

Latest News

Click Pakistan is a professional news-based digital platform led by Editor-in-Chief Syed Tanzil Gillani, delivering credible, timely, and fact-based journalism on national affairs and current events.

© 2026 All Right Reserved. Designed and Developed by Alphabetic Solutions