ToxicPanda 2.0 Expands Android Banking Attacks to 16 Countries

ToxicPanda 2.0 Expands Android Banking Attacks to 16 Countries

First seen 22 Aug 2026, 18:23 UTC ThehackernewsSecurityaffairs.Co 70% similarity 68.0

Article Content

Browse articles
ThreatCluster

ToxicPanda 2.0 has been upgraded to target 349 financial applications across 16 countries, significantly expanding its reach beyond Europe. The malware exploits Android Wireless Debugging to gain unauthorized access to devices and steal banking credentials. This version of ToxicPanda represents a shift from a localized threat to a global one, with implications for financial institutions worldwide. Zimperium's zLabs team has documented these developments, highlighting the urgent need for enhanced security measures. The attack vector leverages vulnerabilities in Android systems, raising concerns about the security of mobile banking applications. As of now, the threat remains active and poses a significant risk to users of the affected financial apps.

Key Points: • ToxicPanda 2.0 targets 349 financial applications across 16 countries. • The malware exploits Android Wireless Debugging for deeper device access. • Zimperium's zLabs team has confirmed the expanded capabilities of ToxicPanda.

ThreatCluster AI How this analysis works

Timeline

2026-08-20
ToxicPanda 2.0 upgrade announced
Zimperium's zLabs documented the upgrade of ToxicPanda, expanding its attack capabilities significantly.
Thehackernews
2026-08-22
ToxicPanda 2.0 targets 349 financial apps
The malware is now targeting a wide range of financial institutions globally, indicating a major shift in its operational scope.
Securityaffairs.Co

Community

Browse all →

Tracked Entities in This Story