← Back to feed
PhishingEmerging1 sourceAug 20, 2026 · 10:32via CyberPress

ToxicPanda 2.0 Targets 349 Financial Apps and Abuses Android ADB for Shell-Level Access

Brief

The malware now targets 349 banking, financial, e-wallet, and cryptocurrency applications across 16 countries, compared with only 16 banking apps in the previously documented version.

ToxicPanda first emerged as an Android banking threat targeting Europe and Latin America. Earlier research found that several remote commands were unfinished, but the newer version reportedly implements many of these functions and expands the malware’s command set to 167 commands.

Previous analysis also linked ToxicPanda to on-device fraud operations, where attackers remotely operate a victim’s legitimate banking session.

ToxicPanda 2.0 Abuses Android ADB

The updated malware abuses Android Accessibility Services to automate user-interface actions, read screen elements, capture touch input, and deploy phishing overlays.

Read more on CyberPress