Malware overlays on top of the victim’s screen | Image: zLabs
At a glance
| Factor | Details |
|---|---|
| Malware Family | ToxicPanda 2.0 |
| Threat Actor | Unconfirmed (Suspected Chinese-speaking actors) |
| Targets | Android users of 349 financial apps across 16 countries |
| Delivery Vector | AWS-hosted buckets via fake system updates and VPN installers |
| Key Capabilities | 167 remote commands, PIN theft, ADB abuse, automated overlays |
| Source | Zimperium zLabs |
TL;DR
The ToxicPanda 2.0 banking Trojan is an aggressive mobile malware strain targeting hundreds of banking and cryptocurrency applications worldwide. Attackers deploy malicious overlays to capture PINs and bypass standard security checks. This updated threat relies heavily on Accessibility Service abuse and cloud infrastructure to hijack Android endpoints.
Delivery
The operators of the ToxicPanda 2.0 banking Trojan deploy the malware by presenting a deceptive installation interface to unsuspecting Android users. Recent campaign analysis reveals a distinct shift in distribution tactics, as attackers now deliver the malware directly from Amazon AWS-hosted buckets. This indicates that the threat actors are using legitimate cloud infrastructure to evade network detection systems.
Initially, the dropper application disguises itself as a common utility or a critical system update to lower the victim’s guard. Then, the malware first requests VPN service privileges to block network communication from Google Play and Google Play Services on the compromised device. Once the user approves the deceptive request, the dropper decrypts the actual payload stored within its internal assets folder. Afterward, it completes the silent installation.
Infection Chain
After a successful deployment, the malware aggressively requests Android Accessibility Service permissions. Once the victim grants this access, the software intercepts user interface elements and launches deceptive screen overlays to steal lock-screen credentials. Additionally, the malware actively monitors the device for the launch of 349 specific financial applications across 16 regions. These regions include Mexico, South Africa, and Pakistan. This is a massive increase compared to the previous version, which targeted only 16 banking applications. When a targeted application opens, the malware retrieves a matching HTML overlay from the command server. It then displays it over the genuine application. These overlays perfectly replicate authentic login screens. Consequently, they trick users into entering their passwords and PINs.
Furthermore, these ToxicPanda 2.0 banking Trojan attacks introduce an automated click-based mechanism to abuse the Android Wireless Debugging feature. First, the malware verifies if Developer Options are active. If they are disabled, it simulates rapid screen taps to unlock developer mode automatically. After doing so, it navigates to the wireless debugging menu, activates the switch, and scrapes the dynamically generated pairing code. Armed with this code, the malware authenticates a local pairing handler with the ADB daemon. This grants the malware dangerous shell-level privilege escalation. As a result, it can change device passwords, bypass battery optimization limits, and enforce long-term persistence without further user interaction. In many cases, the malware conceals these background actions by displaying a fake system update screen.
Command-and-Control and Data Exfiltration
Upon infection, the malware establishes low-latency, bidirectional communication with its command-and-control server using a persistent WebSocket connection. This network traffic remains concealed through AES encryption in ECB mode. In addition, the malware now supports an expansive set of 167 remote commands. These commands grant the operators extensive administrative control over the compromised device.
For example, the remote view switch command allows the malware to programmatically identify and accept system permission dialogs across various Android manufacturer environments. Additionally, the malware can execute a specific password command to force-reset the device’s local lock screen PIN. This enables threat actors to lock out the legitimate user entirely. The operators also utilize remote commands to bypass aggressive vendor-specific power management features. Thus, they ensure the malware is never terminated to conserve battery. Threat actors collect all intercepted PINs, user credentials, and stolen screen data. These are then rapidly exfiltrated over the encrypted channel.
Defense and Detection Guidance
Protecting mobile endpoints against these ToxicPanda 2.0 banking Trojan attacks requires strict oversight of application permissions. While the original malware variants were suspected to originate from Chinese-speaking developers, attribution for this specific operation remains unconfirmed. Therefore, users must exercise extreme caution before granting Accessibility Services or VPN rights to any downloaded application. These permissions form the foundation of the attack.
Security teams should deploy advanced mobile threat defense solutions to monitor for unauthorized Android Debug Bridge pairing attempts and anomalous screen overlay activities. In fact, a recent report from the zLabs team noted, “ToxicPanda 2.0 continues to abuse Android Accessibility Services to enable remote control capabilities and automate fraudulent activities, similar to its previous variants.” By applying the latest Android security patches and avoiding sideloaded applications, users can minimize their exposure to this rapidly evolving threat.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!