Find notable cyber news and cases, enriched with sources, timelines, and signals.

ToxicPanda 2.0 Android banking trojan expansion

Malware Activity
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial institutions across 16 countries. It also abuses Android Accessibility Service and wireless debugging to obtain shell access and run high-privilege ADB commands. The malware can steal device lock credentials through a screen-overlay attack, helping attackers maintain persistent access to compromised devices. Compared with the first version’s 16 banking apps, the new variant is a much broader credential-theft threat.

Related Happenings

ToxicPanda 2.0 Android malware expands fraud capabilities

Malware Activity
H score29 First: 20.08.2026 13:38 Last: 20.08.2026 13:38 Sources 1

About this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...

Manic Android malware activity with offline relay exfiltration

Malware Activity
H score27 First: 20.08.2026 13:02 Last: 20.08.2026 13:02 Sources 1

About this happening: The Manic Android malware is active across multiple European countries, with Ukraine as its main focus, and its fallback exfiltration path can keep data moving eve...

WindRelay NFC relay malware deployed with SpyNote RAT

Malware Activity
H score20 First: 12.08.2026 17:30 Last: 12.08.2026 17:30 Sources 1

About this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...

RedHook Android malware abuses Wireless ADB for shell access

Malware Activity
H score26 First: 12.07.2026 17:27 Last: 12.07.2026 17:27 Sources 1

About this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...

RedWing Android spyware rented through Telegram

Malware Activity
H score21 First: 08.07.2026 18:30 Last: 08.07.2026 18:30 Sources 1

About this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...

Timeline

  1. 20.08.2026 13:00 2 articles · 1h ago

    Zimperium zLabs identifies ToxicPanda 2.0 with expanded Android credential theft

    Technical Analysis Update

    Zimperium zLabs identified ToxicPanda 2.0 as a new Android banking Trojan variant that uses PIN theft and overlay-based credential theft against 140 banking and cryptocurrency apps and 349 financial institutions across 16 countries, and it abuses Android Accessibility Service and wireless debugging to obtain shell access, run high-privilege ADB commands, bypass consent prompts, and maintain persistence on compromised devices.

    Show sources