Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Bitcoin Rally Accelerates, With $80,000 In Sight

    August 24, 2026

    NASA Research Shows How Sun’s Ancient History Shaped Earth

    August 24, 2026

    Bangladesh’s green building drive grows beyond factories amid climate pressures

    August 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Bitcoin Rally Accelerates, With $80,000 In Sight
    • NASA Research Shows How Sun’s Ancient History Shaped Earth
    • Bangladesh’s green building drive grows beyond factories amid climate pressures
    • DNV augments subsea toolkit with Equinor’s wellhead fatigue tech
    • The Guardian view on Britain helping Ukraine: build the weapons independence Kyiv needs | Editorial
    • Kennedy Distorts Stat in Celebrating Obesity Drop
    • Saudi Arabia to invest €6 billion in theme parks near Paris, Macron says
    • Trump announces 50 percent tariff on Canadian vehicles, steel after trade talks collapse
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ToxicPanda Banking Trojan Matures Into Enterprise Threat

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 24, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An Android banking Trojan has resurfaced with a new variant that demonstrates a significant evolution toward full device compromise and persistent access, putting at risk not only mobile users but also the enterprise resources accessed from those devices.

    ToxicPanda 2.0 expands substantially on its predecessor, adding 167 remote commands and broadening its targeting from 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications, according to recent research from Zimperium zLabs. The Trojan also adds more sophisticated techniques for compromising Android devices, including privilege escalation and shell-level access through Android’s Wireless Debugging and Android Debug Bridge (ADB), as well as capabilities designed to maintain long-term persistence on infected devices.

    ToxicPanda first emerged in November 2024, when it was observed taking over Android devices and facilitating fraudulent mobile banking transactions in Latin America, Italy, Portugal, and Spain. Its expansion into 16 countries and the addition of significantly more functionality indicate a more mature and capable threat than the initial version researchers encountered.

    Related:Video Call Exploit Chains Two Flaws in Unisoc Modems

    Overall, the updated version “demonstrates a significant expansion in targeting scope and capabilities,” Zimperium zLabs researcher Vishnu Pratapagiri wrote in the report.

    ToxicPanda Grows Up

    One notable change in ToxicPanda 2.0 is its distribution infrastructure. Researchers observed samples being delivered through Amazon Web Services-hosted buckets, suggesting that the operators are leveraging legitimate cloud infrastructure to distribute the malware.

    The variant also introduces a lock-screen overlay designed to capture credentials entered by the victim. The capability potentially expands the Trojan’s impact beyond banking fraud by giving attackers access to credentials that can help unlock the device and potentially gain access to other services.

    “The device this Trojan takes over is the same device that approves push MFA prompts, holds passkeys, and runs the banking and wallet apps for the employee and the company both,” says Bradley Smith, senior vice president and deputy chief information security officer (CISO) at BeyondTrust. “When malware can steal the lock screen PIN through an overlay and then reset the device password through admin privileges, the attacker walks away with the identity anchor and every account standing behind it.”

    ToxicPanda 2.0 also abuses Android’s Wireless Debugging capability, introduced in Android 11, as a mechanism for privilege escalation. Wireless Debugging is normally intended for developers who want to connect to an Android device through ADB without a physical USB connection.

    Related:Fake Bahrain Alert App Deploys Android Surveillance Malware

    ToxicPanda automates that process using Android’s Accessibility Services. It can enable Developer Options, turn on Wireless Debugging, extract the temporary ADB pairing code, and complete the pairing process with the device’s ADB service, according to Zimperium.

    The result is particularly significant because the malware obtains shell-level access, allowing it to execute commands directly on the device. From there, threat actors can grant themselves additional permissions, weaken operating-system restrictions, enable components, and establish persistence. In effect, the malware is abusing legitimate Android administration functionality to move from application-level capabilities toward deeper control of the device itself.

    A Broader Enterprise Threat

    ToxicPanda 2.0’s evolution reflects a wider trend among banking Trojans. These threats increasingly go beyond compromising individual banking applications for financial gain and instead seek persistent control of the underlying device.

    That shift creates a potential enterprise security problem. A compromised employee smartphone can simultaneously serve as a banking device, an authentication device, a repository for passkeys, and a gateway to corporate applications and services.

    Related:Fake Android Apps Commit Carrier Billing Fraud for Premium Services

    The risk therefore extends beyond the financial applications directly targeted by the malware. If attackers can establish persistent control of the device, they may have opportunities to interfere with authentication, steal credentials, manipulate applications, or use the compromised endpoint as a stepping stone toward other enterprise resources.

    “As mobile banking threats like ToxicPanda become increasingly sophisticated, conventional signature-based security layers are no longer sufficient to protect enterprise mobile endpoints,” Pratapagiri wrote. Zimperium recommended comprehensive, multilayered protection capable of disrupting the malware at multiple stages of its attack chain.

    For enterprises, BeyondTrust’s Smith recommends several controls to mitigate the expanded capabilities of banking Trojans like ToxicPanda 2.0. Organizations should block sideloading on devices enrolled in corporate identity systems and treat Accessibility Service grants as privileged-access events that should be logged and reviewed, he says.

    Organizations should also alert when Developer Options or Wireless Debugging is enabled on managed mobile devices. “That is a sign your mobile device management can already see,” Smith says, “and few are watching for it.”

    banking enterprise Matures threat ToxicPanda Trojan
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

    WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

    ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

    ReliaQuest confirms failed data-theft attack after ShinyHunters breach

    Microsoft Teams now lets admins block external bots from meetings

    Microsoft: August updates break printing, PDF export in WPF apps

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Bitcoin Rally Accelerates, With $80,000 In Sight

    August 24, 2026

    NASA Research Shows How Sun’s Ancient History Shaped Earth

    August 24, 2026

    Bangladesh’s green building drive grows beyond factories amid climate pressures

    August 24, 2026

    DNV augments subsea toolkit with Equinor’s wellhead fatigue tech

    August 24, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Bitcoin Rally Accelerates, With $80,000 In Sight

    August 24, 2026

    NASA Research Shows How Sun’s Ancient History Shaped Earth

    August 24, 2026

    Bangladesh’s green building drive grows beyond factories amid climate pressures

    August 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.