ToxicPanda 2.0 Android malware has added powerful new capabilities, including VPN traffic interception, wireless Android Debug Bridge (ADB) abuse, and expanded phishing overlays targeting 349 banking, cryptocurrency, financial, and e-wallet applications across 16 countries.
The latest version also supports 167 remote commands, giving attackers extensive control over infected Android devices. Researchers from mobile security company Zimperium say the malware is distributed through Amazon Web Services (AWS)-hosted buckets.
ToxicPanda 2.0 requests access to the Android VPN service to create a local network interface. This allows the malware to monitor and control traffic passing through the device, including communications involving Google Play and Google Play Services.
By blocking Google Play traffic, the malware can interfere with app validation, security updates, Play Protect communications, and other protections designed to detect malicious activity or safeguard users.
After obtaining VPN access, ToxicPanda 2.0 blocks Google Play and Google Play Services communications before requesting Android Accessibility Service permissions. The malware uses those permissions to extract and install additional payloads.

ToxicPanda targets banking and cryptocurrency apps
Zimperium’s analysis found that ToxicPanda 2.0 includes phishing overlays designed to target 349 banking, financial, cryptocurrency, and e-wallet applications across 16 countries. The malware can display fraudulent interfaces over legitimate apps to steal sensitive information.
The malware also includes a separate PIN-stealing module targeting 140 financial and cryptocurrency applications. Its target list can be updated dynamically, allowing attackers to add new apps without distributing an entirely new malware sample.
Researchers say the malicious overlays are designed to remain hidden from victims while capturing touch input entered into targeted applications.
ToxicPanda can also imitate the Android lock screen to steal a device’s PIN, unlock pattern, or password. Some analyzed samples displayed fake system-update screens to conceal malicious activity while the malware continued operating in the background.

Source: Zimperium
One command, autoBoot, identifies the device manufacturer and configures the corresponding OEM-specific autostart and power-management settings. This helps ToxicPanda maintain persistence and bypass battery-optimization features that terminate background processes on devices from Xiaomi, OPPO, Vivo, Samsung, and Huawei.
More technical details are available in the Zimperium report.
ToxicPanda abuses wireless Android Debug Bridge
One of the most notable features in the latest ToxicPanda samples is the automated abuse of the Android Debug Bridge, or ADB, to gain shell-level access to infected devices.
ADB is a command-line tool that allows commands to be executed on Android devices. Android 11 introduced wireless debugging, enabling ADB connections over Wi-Fi without requiring a USB cable.
ToxicPanda uses Accessibility Service permissions to enable Developer Options, turn on wireless debugging, and retrieve the six-digit ADB pairing code and port needed to connect to the device’s local ADB service.

“Once the malware acquires the shell user’s privileges, it begins executing high-privileged commands directly through the ADB daemon. Bypassing the standard Android runtime consent prompt, the malware grants itself broad privileges, disables OS background restrictions, silently enables critical components, and enforces persistence,” Zimperium explains.
Wireless ADB abuse is becoming an increasingly common technique in Android malware. Group-IB recently reported that the latest version of the RedHook malware also uses a similar mechanism to obtain access to infected devices.
ToxicPanda 2.0 indicators of compromise
Zimperium has published indicators of compromise (IoCs) associated with the latest ToxicPanda 2.0 Android malware samples. The IoCs are available in the researchers’ GitHub repository.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




