ToxicPanda 2.0 Blocks Google Play as Android Malware Targets 349 Financial Apps

ToxicPanda 2.0 now targets 349 financial apps across 16 countries while abusing VPN, Accessibility and Android debugging features for deeper control.

Aug 25, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

ToxicPanda 2.0 is giving attackers deeper remote control over infected Android phones, including a new way to keep Google Play out of the way.

Security researchers at Zimperium’s zLabs have uncovered a new version of the ToxicPanda Android banking Trojan with a far wider reach and a much larger arsenal of commands.

The malware now supports 167 remote commands and can target 349 banking, financial, e-wallet and cryptocurrency applications across 16 countries, up from 16 banking apps in the previously documented version, according to Zimperium.

ToxicPanda 2.0 can also steal PINs from more than 140 financial and cryptocurrency apps, capture device unlock credentials and manipulate Android settings to maintain access.

Zimperium said the new version “demonstrates a significant expansion in targeting scope and capabilities.”

Google Play gets cut off

The attack begins with a dropper that disguises its installation process and asks the victim to grant VPN privileges. Once approved, the malware uses the VPN interface to block network communications from Google Play and Google Play Services before decrypting and installing its hidden payload, Zimperium found.

The malware then asks for Android Accessibility Service access. That legitimate feature gives ToxicPanda the ability to inspect screen elements, automate taps, and interact with applications.

Samples are being delivered from Amazon Web Services-hosted storage buckets, according to Zimperium, showing that the operators are also using mainstream cloud infrastructure to distribute the malware.

ADB opens a deeper door

One of ToxicPanda 2.0’s more concerning additions is its abuse of Android Wireless Debugging, a legitimate developer feature.

Using Accessibility Services, the malware can enable Developer Options, turn on Wireless Debugging, open the device’s pairing screen, and extract the temporary six-digit pairing code. It then pairs with the device’s local Android Debug Bridge service.

That can give the malware shell-level access, allowing attackers to execute commands, grant additional permissions, weaken background restrictions and improve persistence without relying entirely on normal Android permission prompts.

The Trojan can also use fake Android lock screens to steal PINs, patterns and passwords. Other samples display deceptive full-screen “system update” screens to hide malicious activity.

Advertisement

What it means for users and businesses

The bigger risk is that ToxicPanda is no longer simply a tool for stealing banking credentials. Its ability to control the device, manipulate settings and operate inside legitimate banking sessions creates a broader account-takeover threat.

For businesses, a compromised employee phone could also be an authentication device containing passkeys, banking apps and access to corporate services, Dark Reading reported.

That makes sideloading the biggest decision point for users. ToxicPanda still needs victims to install the malicious app and approve powerful permissions. Avoiding APKs from unsolicited links and treating unexpected requests for Accessibility, VPN, Device Administrator or Developer Options access as warning signs can cut off the attack before the malware gains control.

ToxicPanda 2.0’s most important evolution may not be any single feature. It is the way the malware chains legitimate Android functions together.

Accessibility Services, VPN functionality, Wireless Debugging, and device administration all have legitimate uses. Once granted to a malicious app, however, those capabilities can be combined to give attackers increasingly deep control over the device.

That complicates defense because organizations cannot simply disable every feature ToxicPanda abuses. The more practical signal is the combination: unexpected Accessibility activity, Developer Options changes, Wireless Debugging activation, and unexplained ADB pairing should warrant closer investigation on managed Android devices.

Other News: A suspected Iran-linked cyberattack reportedly forced a small U.K. power generator offline for 4 days, highlighting growing concerns about the resilience of critical infrastructure to cyber threats. 

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.