ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
Summary
Hide ▲
Show ▼
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial institutions across 16 countries. It also abuses Android Accessibility Service and wireless debugging to obtain shell access and run high-privilege ADB commands. The malware can steal device lock credentials through a screen-overlay attack, helping attackers maintain persistent access to compromised devices. Compared with the first version’s 16 banking apps, the new variant is a much broader credential-theft threat.
Related Happenings
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware Activity
H score29
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
About this happening:
The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware ActivityAbout this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score27
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
The Manic Android malware is active across multiple European countries, with Ukraine as its main focus, and its fallback exfiltration path can keep data moving eve...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: The Manic Android malware is active across multiple European countries, with Ukraine as its main focus, and its fallback exfiltration path can keep data moving eve...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware Activity
H score20
First: 12.08.2026 17:30
Last: 12.08.2026 17:30
Sources 1
About this happening:
WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware ActivityAbout this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
RedHook Android malware abuses Wireless ADB for shell access
Malware Activity
H score26
First: 12.07.2026 17:27
Last: 12.07.2026 17:27
Sources 1
About this happening:
The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedHook Android malware abuses Wireless ADB for shell access
Malware ActivityAbout this happening: The RedHook Android malware now abuses Wireless ADB to obtain shell (UID 2000) privileges, expanding its control over infected devices. The change lets the malware ope...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
Timeline
-
20.08.2026 13:00 2 articles · 1h ago
Zimperium zLabs identifies ToxicPanda 2.0 with expanded Android credential theft
Technical Analysis UpdateZimperium zLabs identified ToxicPanda 2.0 as a new Android banking Trojan variant that uses PIN theft and overlay-based credential theft against 140 banking and cryptocurrency apps and 349 financial institutions across 16 countries, and it abuses Android Accessibility Service and wireless debugging to obtain shell access, run high-privilege ADB commands, bypass consent prompts, and maintain persistence on compromised devices.
Show sources
- Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps — www.infosecurity-magazine.com — 20.08.2026 13:00
- Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps — www.infosecurity-magazine.com — 20.08.2026 13:00