Zimperium has revealed new findings from its zLabs threat research team that uncover the evolving threat of ToxicPanda 2.0, a sophisticated Android banking trojan. This new iteration signifies a significant enhancement in both the technical prowess and the scale of the trojan’s fraud activities.
The upgraded version of the original ToxicPanda banking trojan introduces 167 remote commands, dramatically extending its ability to steal credentials. Its reach has now expanded from a select few banking applications to include 349 banking, financial, e-wallet, and cryptocurrency apps, impacting users across 16 countries. Furthermore, the trojan employs advanced techniques to infiltrate Android devices, extract banking information, and ensure long-term presence in the affected devices.
Rising threat with mobile adoption
As the use of mobile applications for banking, enterprise functions, digital identities, and sensitive data continues to soar, the sophistication of Android malware poses a growing threat to both individual consumers and businesses.
The upgraded version of the original ToxicPanda banking trojan introduces 167 remote commands
Nico Chiaraviglio, Chief Scientist at Zimperium zLabs, commented, "ToxicPanda 2.0 demonstrates how quickly mobile malware continues to evolve. Rather than simply stealing credentials, this malware automates device compromise, expands financial targeting on a global scale, and abuses legitimate Android features to gain control over infected devices. It reflects the increasing sophistication of modern mobile threats."
Advanced threat detection
Zimperium's AI-based, on-device mobile security solutions are designed to protect organisations against advanced threats like ToxicPanda.
These solutions are capable of identifying malware, device compromises, phishing overlays, and malicious application behaviours before attackers can exploit these vulnerabilities to steal credentials or seize control of the target device.
