Particle.news
Download on the App Store

ToxicPanda 2.0 Hijacks Android Features to Take Over Phones and Banking Apps

Researchers warn the campaign automates Wireless ADB, Accessibility and VPN misuse to gain shell access, block Play Protect, harvest PINs, persist

Overview

  • Security researchers this week disclosed ToxicPanda 2.0 as a live, upgraded Android banking trojan that now targets 349 financial apps across 16 countries and supports 167 remote commands.
  • The dropper requests VPN permission to create a local interface that blocks Google Play and Play Protect while it decrypts and installs the real payload.
  • Once installed the malware uses Accessibility permissions to read the screen, deploy invisible overlays to capture touches and PINs, spoof the lock screen, and click through OEM permission dialogs to gain more rights.
  • ToxicPanda fully automates Wireless ADB by enabling Developer Options, extracting the six-digit pairing code from the screen, performing the pairing handshake, and using ADB shell commands to grant broad permissions and enforce persistence.
  • Samples are now delivered from Amazon AWS buckets which makes simple IP blocking harder, so defenders are urged to monitor Accessibility and developer/debug events, block sideloading on managed devices, deploy mobile threat defense, and follow published IOCs to detect and remove infections.