ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
Summary
Hide ▲
Show ▼
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial institutions across 16 countries. It also abuses Android Accessibility Service and wireless debugging to obtain shell access and run high-privilege ADB commands. The malware can steal device lock credentials through a screen-overlay attack, helping attackers maintain persistent access to compromised devices. Compared with the first version’s 16 banking apps, the new variant is a much broader credential-theft threat.
Related Happenings
StreamRat Android banking trojan with remote-control capabilities
Malware Activity
H score42
First: 02.09.2026 15:22
Last: 02.09.2026 15:22
Sources 1
About this happening:
The StreamRat Android banking trojan is being pushed through fake streaming ads on Meta and can yield near-complete device control, raising the risk of credentia...
StreamRat Android banking trojan with remote-control capabilities
Malware ActivityAbout this happening: The StreamRat Android banking trojan is being pushed through fake streaming ads on Meta and can yield near-complete device control, raising the risk of credentia...
Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults
Security Tool/Service
H score15
First: 28.08.2026 19:20
Last: 28.08.2026 19:20
Sources 1
About this happening:
Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client He...
Android 17 adds OS-wide ECH, Local Network Protection, CT by default, and carrier 2G-off defaults
Security Tool/ServiceAbout this happening: Android 17 adds OS-wide network protections that reduce traffic metadata exposure and limit local-network and cellular attack surfaces. The update brings Encrypted Client He...
WhatsApp rolls out multiple passkeys, stronger two-step verification, and scam-call context
Security Tool/Service
H score11
First: 25.08.2026 16:00
Last: 25.08.2026 16:00
Sources 1
About this happening:
WhatsApp is rolling out new account security controls that expand passkey support, strengthen two-step verification, and add more call-screen scam context for...
WhatsApp rolls out multiple passkeys, stronger two-step verification, and scam-call context
Security Tool/ServiceAbout this happening: WhatsApp is rolling out new account security controls that expand passkey support, strengthen two-step verification, and add more call-screen scam context for...
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware Activity
H score29
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
About this happening:
The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware ActivityAbout this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score29
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: Manic is an Android malware activity that targets Ukrainian banks, government and identity services, messaging apps, and also Russian and European financial inst...
Timeline
-
20.08.2026 13:00 2 articles · 13d ago
Zimperium zLabs identifies ToxicPanda 2.0 with expanded Android credential theft
Technical Analysis UpdateZimperium zLabs identified ToxicPanda 2.0 as a new Android banking Trojan variant that uses PIN theft and overlay-based credential theft against 140 banking and cryptocurrency apps and 349 financial institutions across 16 countries, and it abuses Android Accessibility Service and wireless debugging to obtain shell access, run high-privilege ADB commands, bypass consent prompts, and maintain persistence on compromised devices.
Show sources
- Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps — www.infosecurity-magazine.com — 20.08.2026 13:00
- Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps — www.infosecurity-magazine.com — 20.08.2026 13:00