"What stands out to me in this research is that ToxicPanda 2.0 does not break Android, it operates Android," BeyondTrust deputy CISO Bradley Smith argued.
That observation frames the security risk identified on August 19 by Zimperium’s zLabs team: a significantly upgraded variant of the Android banking Trojan known as ToxicPanda. The new iteration—ToxicPanda 2.0—widens its scope from a handful of targets to hundreds, adding capabilities that let attackers request live overlays, harvest PINs and device-lock credentials, and escalate to shell-level access by abusing legitimate platform features.
ToxicPanda 2.0 expands its target set: 140 apps, 349 institutions
Zimperium’s zLabs reported that ToxicPanda 2.0 includes a PIN-theft mechanism designed to target 140 banking and cryptocurrency applications and an overlay-based credential-theft mechanism targeting 349 financial institutions. That is a large jump from the first iteration of the malware, which targeted 16 banking apps.
The report says that when a victim launches one of the targeted applications, the malware requests the relevant malicious HTML overlay from its command-and-control (C2) server—an approach that lets the attacker present fake login or PIN input screens to harvest credentials in real time.
Overlay attacks and persistent device access
Alongside expanded targeting, ToxicPanda 2.0 adds a screen overlay attack capable of stealing device lock credentials, a change that can grant an attacker persistent access to a compromised device. The overlay technique is paired with the HTML overlays pulled from the C2 server to capture both app credentials and device-level authentication.
The zLabs write-up emphasizes that these overlays are requested dynamically when a targeted app is launched, allowing the malware to tailor its social-engineering screens to the victim’s active app and context.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAbuse of Accessibility Service and wireless debugging to gain shell access
One of ToxicPanda 2.0’s most notable technical additions is its abuse of the Android Accessibility Service to enable wireless debugging, effectively trying to turn that legitimate functionality into a route to shell access. Zimperium quotes the report: “Once the malware gains shell user permissions, it starts executing high-privilege commands directly through the ADB [Android Debug Bridge] daemon.”
The report continues that the malware “bypasses standard Android runtime consent prompts to grant itself broad permissions, neutralize OS background restrictions, silently enable critical components, and enforce persistence.” In short, ToxicPanda 2.0 uses designed platform features to elevate privileges and maintain long-term control rather than relying solely on software vulnerabilities.
Geographic footprint: 16 countries with strong presence in five
Zimperium’s analysis identifies financial institutions across 16 countries among the overlay targets. Most of these institutions are located in Pakistan, South Africa, Mexico, Nigeria and India, signaling the campaign’s emphasis on markets outside the usual Western banking app ecosystems.
Three concrete mitigations from BeyondTrust’s deputy CISO
Bradley Smith of BeyondTrust recommended three controls enterprises can deploy to blunt ToxicPanda’s impact:
- Block sideloading on any device enrolled in corporate identity.
- Treat accessibility service grants as privileged access events, subject to logging and review.
- Alert when developer options or wireless debugging switch on across the managed fleet—functionality that is observable through mobile device management (MDM) tooling.
Smith framed these recommendations around a central problem: the malware leverages legitimate platform features. “We've been seeing this pattern across mobile threats all year: abuse of legitimate platform features, accessibility services above all, rather than exploitation of vulnerabilities. There is no patch for a feature working as designed, so the control plane must move from patching to governing who and what gets those grants.”
What this means for security teams, enterprise IT, and mobile users
- Security teams and technologists: Expect to monitor and log accessibility-service grants and wireless debugging activity; detection should focus on anomalous enabling of these features and the presence of overlays tied to C2 activity.
- Enterprise IT and procurement: Enforce MDM controls that block sideloading for managed devices and configure alerts for developer options or wireless debugging changes to the fleet.
- End users and device owners: Be cautious about enabling developer options or accepting accessibility grants from apps; overlays and fake login screens can be delivered dynamically when a targeted app is opened.
ToxicPanda 2.0 illustrates a broader shift: attackers are increasingly weaponizing legitimate platform capabilities to achieve the same ends that exploits once provided. Zimperium’s findings and BeyondTrust’s recommendations converge on one clear operational implication—governance of platform features must be elevated to a first-order defense where patching alone cannot remove the risk.
Read the Zimperium / infosecurity write-up here: https://www.infosecurity-magazine.com/news/updated-toxicpanda-140-banking/




