ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries — Threadlinqs Intelligence
As of 2026-08-24, ToxicPanda 2.0 Android Banking Trojan Expands to 349 Financial Institutions Across 16 Countries is a high-severity malware threat attributed to a China-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-2128 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: China · FINANCIAL
ToxicPanda, an Android banking trojan first disclosed by Cleafy in late 2024 targeting Europe and Latin America, has matured into version 2.0 with 167 remote commands and phishing-overlay coverage of
ToxicPanda 2.0 is a major capability escalation of the ToxicPanda Android banking trojan. Later reporting (The Hacker News, citing Zimperium) places the family's activity as far back as approximately July 2022, but it was first publicly documented by Cleafy Labs in November 2024 as a Southeast-Asia-origin family -- sharing 61 commands with the TgToxic trojan, and carrying artifacts pointing to Chinese-speaking operators, including a hardcoded reference to the Chinese 114DNS resolver (114.114.114.114) and embedded Chinese-language strings. That original wave infected over 1,500 Android devices across 16 banking apps, delivered via social-engineered side-loading using icons that mimicked Chrome, VISA, and dating apps, and concentrated in Italy (56.8% of infections), Portugal (18.7%), Hong Kong (4.6%), with further activity in Spain, Peru, France, Germany, and the UK; it used three hardcoded C2 domains (dksu[.]top, mixcom[.]one, freebasic[.]cn) and a static AES-ECB key, and already supported on-device-fraud (ODF) account takeover, OTP interception, and photo-album exfiltration.
Zimperium zLabs' August 2026 analysis shows the operators have since rebuilt the malware into a 167-command remote-access platform with fake phishing overlays covering 349 banking, financial, e-wallet, and cryptocurrency applications across 16 countries, with reporting naming Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama among the targeted markets.
The infection chain begins with a dropper that requests VPN service privileges (to block Google Play Protect communication) and presents a fake WebView-based installation interface before decrypting and installing the main payload from the app's assets folder. On first run the payload requests Accessibility Service permission, enumerates the device's installed applications, and transmits their package names and icons to the C2 as part of registration. It then abuses Accessibility extensively: to auto-grant subsequent dangerous permissions and dismiss system dialogs (`catAllViewSwitch`), to steal on-screen UI elements and keystrokes, and to render phishing overlays -- including fake system-update screens, fake full-screen lock screens, a generic remote-URL full-screen WebView loader (`transparent`, used to push arbitrary attacker-hosted phishing pages), and transparent touch-capturing overlays -- on top of the 349 targeted financial apps. A dedicated PIN-theft subsystem (targeting 140+ banking/crypto apps) places an invisible overlay over the banking keypad to record taps, with the C2-updatable `replacePinTargets`/`addPinTargets` commands letting operators retarget apps without shipping a new build.
The most significant new capability is a fully automated wireless-ADB privilege-escalation chain, described by Zimperium as "an automated click-based mechanism to abuse Android Wireless Debugging (ADB), enabling privilege escalation and shell-level access on compromised devices." Using Accessibility, the malware opens Settings > About Phone, queries the accessibility node tree for the "Build number" row, and simulates seven rapid taps to unlock Developer Options; it then fires an `APPLICATION_DEVELOPMENT_SETTINGS` intent, locates and toggles "Wireless debugging" on, opens "Pair device with pairing code," and polls the resulting modal's accessibility layout to scrape the 6-digit SPAKE2 pairing code and dynamic port. It instantiates a local SPAKE2 pairing handler, opens a TLS-encrypted channel to the ADB daemon on 127.0.0.1, completes the SPAKE2 key exchange with the scraped code, and trades peer-identity metadata to finish pairing -- yielding authenticated shell-level access that bypasses Android's normal runtime consent prompts, without physical device contact or user awareness. This shell access is combined with Device Administrator API abuse: `admSet` fires an `android.app.action.ADD_DEVICE_ADMIN` intent under the social-engineering lure "System service requires administrator privileges,"
Target sectors: banking, financial services, e-wallet digital payments, cryptocurrency
Target regions: pakistan, south africa, mexico, nigeria, india, indonesia, panama, italy, portugal, spain, france, germany
Timeline
- Cleafy Labs publicly discloses the original ToxicPanda Android banking trojan, reporting a botnet of 1,500+ infected devices concentrated in Italy (56.8%) and Portugal (18.7%) and targeting 16 banking apps across Italy, Portugal, Spain, France, Peru, Hong Kong, and the UK, delivered via icon-mimicry side-loading (fake Chrome/VISA/dating apps) and linked to the TgToxic malware family via 61 shared commands and Chinese-language/DNS artifacts.
- Zimperium zLabs publishes analysis of ToxicPanda 2.0, documenting expansion to 349 targeted financial institutions across 16 countries, 167 remote commands, and new wireless-ADB-debugging plus Device Administrator abuse techniques.
- Zimperium publishes the ToxicPanda 2.0 IOC set -- C2 domains, ~120 payload and ~60 dropper SHA-256 hashes, AWS S3/Telegram distribution URLs, and the full 167-command reference -- to its public GitHub IOC repository (2026-08-ToxicPanda).
- The Hacker News, SecurityWeek, cybersecuritynews.com, SC Media, and Infosecurity Magazine publish coverage of ToxicPanda 2.0's expanded targeting, wireless-ADB privilege escalation, and AWS-hosted distribution infrastructure.
- The Hacker News reports, citing Zimperium, that ToxicPanda has reportedly been active since approximately July 2022 -- predating its first public documentation by over two years -- and covers ToxicPanda 2.0 alongside the separate, unrelated GoldDigger/GoldFactory Android banking-malware campaign in the same roundup.
- SecurityWeek reports ToxicPanda 2.0's 16-country target list by name for the first time, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, and Panama, and quotes Zimperium's description of the wireless-ADB abuse as an 'automated click-based mechanism.'
- Threadlinqs Intelligence Platform HUNT phase identifies and grounds the ToxicPanda 2.0 campaign from the verified Zimperium primary source after an assigned Dark Reading source URL returned HTTP 403.
- Threadlinqs Intelligence Platform completes RESEARCH-phase documentation of ToxicPanda 2.0 as TL-2026-2128.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1660, T1655.001, T1407, T1406, T1628.001, T1541, T1626.001, T1453, T1417.001, T1417.002