ToxicPanda Android Malware Expands to 349 Finance Apps
Zimperium identifies the version as ToxicPanda 2.0, an evolution of a campaign first documented by Cleafy in 2024. Cleafy linked the earlier operation to on-device fraud, in which criminals remotely manipulate a victim's enrolled handset to initiate transactions. Its earlier telemetry covered more than 1,500 compromised Android devices, concentrated in Italy, Portugal and Spain, but that historical count should not be treated as an infection total for the new version.
The infection chain described by Zimperium begins with malicious applications delivered from Amazon AWS-hosted buckets rather than Google Play. After installation, the malware requests VPN service permission and creates a local network interface. It then blocks communications with Google Play and Google Play Services before extracting its payload and requesting Accessibility Service access, potentially disrupting app verification, updates and Play Protect communications.
With Accessibility access, ToxicPanda can automate Android Wireless Debugging. Researchers found that it enables Developer Options, turns on Wireless Debugging, obtains the six-digit pairing code and port, and connects to the device's local Android Debug Bridge service. Shell-level access lets the malware grant itself permissions, weaken background restrictions and enable components without relying on the normal Android consent flow. No Android vulnerability or CVE is required for this documented technique.
The malware uses invisible phishing overlays to capture touch input from targeted apps and includes a separate PIN-harvesting module for 140 financial and cryptocurrency applications. It can imitate the Android lock screen to collect PINs, patterns and passwords, while some samples display fake system-update screens to conceal activity. An OEM-aware persistence function opens auto-start or power-management settings on Xiaomi, OPPO, Vivo, Samsung and Huawei devices.
Android users and enterprise mobility teams should block untrusted sideloaded applications, scrutinize unexpected VPN and Accessibility requests, and investigate devices where ordinary apps enable Developer Options or Wireless Debugging. Defenders can use the indicators published with Zimperium's analysis for detection and should isolate suspected devices before resetting credentials from a known-clean system. Financial institutions can also monitor for unusual transactions originating from otherwise trusted enrolled handsets.