ToxicPanda 2.0 Android Banking Trojan Expands Capabilities and Targeting

Security researchers have identified ToxicPanda 2.0, a significantly upgraded Android banking Trojan and remote access tool designed for account takeover and what is being termed ‘on-device fraud.’ This latest iteration demonstrates a marked evolution in mobile malware tactics, combining elements of banking overlays, remote access capabilities, PIN capture workflows, abuse of the Android Accessibility Service, and attempts at Wireless Debugging automation to maximize its effectiveness. The Trojan is distributed through fake applications, phishing campaigns, and payloads hosted on Amazon AWS buckets.

ToxicPanda 2.0’s targeting scope is extensive, aiming at over 140 banking and cryptocurrency applications using a PIN-theft mechanism, as well as 349 financial institutions via overlay-based credential theft. The Trojan utilizes Android’s Accessibility Service to inspect interface elements, observe app activity, automate interactions, and place deceptive content over legitimate apps. After installation, the dropper presents a fake installation flow, requests VPN privileges, blocks certain Google Play and Google Play Services network communications, decrypts an embedded payload, and seeks Accessibility Service permission for the installed payload.

A key advancement in ToxicPanda 2.0 is its introduction of an automated click-based mechanism leveraging Android Debug Bridge (ADB) for privilege escalation. This allows the malware to gain shell-level access to infected devices, significantly increasing its control and persistence. Furthermore, it establishes bidirectional WebSocket communication with a Command and Control (C2) server secured using AES encryption in ECB mode.

The Trojan’s ability to block Google Play communications by requesting malicious VPN service permissions adds another layer of complexity, hindering user awareness and making detection more difficult. Researchers at Zimperium’s zLabs team first discovered ToxicPanda 2.0; malware campaigns are actively targeting financial institutions and end-users globally, with expansion into APAC and Spanish-speaking regions.

Defending against ToxicPanda 2.0 requires a multi-layered approach including robust mobile device management (MDM) policies, user education on phishing threats, and the deployment of advanced threat detection solutions capable of identifying malicious app behavior, especially those leveraging Accessibility Services or attempting to gain ADB access. Organizations should also monitor network traffic for suspicious WebSocket connections and ensure regular security audits of third-party applications.

The continued evolution of ToxicPanda 2.0 highlights the increasing sophistication of mobile malware threats and underscores the need for proactive cybersecurity measures to protect sensitive financial data. Active exploitation has been ongoing since at least July 2022, with an updated version released recently.

Sources: