Overview
- Security researchers this week disclosed ToxicPanda 2.0 as a live, upgraded Android banking trojan that now targets 349 financial apps across 16 countries and supports 167 remote commands.
- The dropper requests VPN permission to create a local interface that blocks Google Play and Play Protect while it decrypts and installs the real payload.
- Once installed the malware uses Accessibility permissions to read the screen, deploy invisible overlays to capture touches and PINs, spoof the lock screen, and click through OEM permission dialogs to gain more rights.
- ToxicPanda fully automates Wireless ADB by enabling Developer Options, extracting the six-digit pairing code from the screen, performing the pairing handshake, and using ADB shell commands to grant broad permissions and enforce persistence.
- Samples are now delivered from Amazon AWS buckets which makes simple IP blocking harder, so defenders are urged to monitor Accessibility and developer/debug events, block sideloading on managed devices, deploy mobile threat defense, and follow published IOCs to detect and remove infections.