TECH
ToxicPanda 2.0: An Android banking Trojan and remote access tool designed for account takeover and "on-device fraud"
Researchers have discovered ToxicPanda 2.0, an Android banking Trojan and remote access tool designed for account takeover and "on-device fraud."
ToxicPanda 2.0 not only targets a much larger list of banks and e-wallets but has also expanded its capabilities by combining banking overlays, remote access, and PIN capture. It exploits Android accessibility services and attempts to automate wireless debugging. Together, these functions enable operators to turn a compromised phone into a platform for account takeover, financial fraud, and long-term device control.
The primary goal is on-device fraud. This means that instead of logging in from an attacker-controlled machine, the operator can perform actions from the victim's infected phone, taking control of the device, IP address, app session, and the behavioral context that banks use to determine whether a transaction is fraudulent.
ToxicPanda 2.0 relies on abusing Android's Accessibility Service—a legitimate feature designed to help people interact with their devices. When a victim grants this permission to a malicious app, the malware can inspect interface elements, monitor app activity, automate interactions, and overlay deceptive content onto legitimate apps (a technique known as "overlaying").
Historically, ToxicPanda has relied on social engineering to persuade users to manually install the malicious Android app rather than downloading it from Google Play. The latest campaign uses AWS-hosted Amazon S3 buckets to distribute ToxicPanda 2.0 samples.
Upon installation, the dropper presents a fake setup flow and issues permission requests. ...uses VPN privileges, blocks specific network communications from Google Play and Google Play Services, decrypts embedded content, and then requests Accessibility Service permission for the installed content.
Consequences may include the theft of banking usernames and passwords, interception or capture of PINs, fraudulent transactions, loss of device access, and exposure of the phone's screen-lock password. An attacker operating within an active banking session from the victim's device may be more likely to bypass controls designed to identify unknown devices or unusual login locations.
How to stay safe...Despite its sophistication, ToxicPanda 2.0 still relies heavily on social engineering to trick victims into installing the malicious app and granting the necessary permissions. Therefore, our key recommendations are:
Avoid installing apps from external sources, especially those linked in unsolicited messages, advertisements, or purported support communications.
Exercise extreme caution regarding requests for accessibility access, device administrator privileges, developer settings, and VPN permissions—especially if the app's need for these permissions is unclear or if you do not fully trust the app.
Use an up-to-date, real-time anti-malware solution on your device capable of detecting and blocking the malicious payload. Malwarebytes for Android detects apps from the ToxicPanda 2.0 campaign as... Android/Trojan.Dropper.agent and Android/Trojan.FakeApp.ACR2401245FC11.
If your device is infected...While a factory reset might be necessary to regain control of an infected device, there are a few things you can try first:
First, put your phone in airplane mode and turn off Wi-Fi and Bluetooth. This can disrupt command-and-control communications and prevent credential theft while you investigate. Use another device to freeze or closely monitor transactions, revoke active sessions, and reset your banking credentials.
Do not interact with fake "system update" screens or unexpected requests regarding accessibility, VPN, device administrator, developer options, or wireless debugging.
Start Android in Safe Mode. Google recommends Safe Mode to help identify issues caused by downloaded apps. Remove recently installed or suspicious apps one by one, restart the device normally, and check if the problem persists.
Start Android in Safe Mode. Google recommends Safe Mode to help identify issues caused by downloaded apps. Remove recently installed or suspicious apps one by one, restart the device normally, and check if the problem persists.
First, remove accessibility access. Go to Settings > Accessibility > Installed apps/Downloaded apps and disable any service you do not recognize. Focus on recently installed apps or anything posing as an update, system component, security tool, document viewer, or banking assistant.
Next, check device administrator rights. Go to Security & privacy > More security settings > Device admin apps and disable any unrecognized administrator before attempting removal. An app with device administrator privileges can make the uninstall option unavailable.
Then, check your VPNs. Go to Settings > Network & internet > VPN (or search for "VPN" in Settings) and delete any VPN profile you did not deliberately install. The ToxicPanda dropper uses VPN permissions as part of the process to block Google Play and Google Play Services.
Disable dangerous developer features. Search for "Developer options" in Settings, turn them off completely, and ensure that Wireless debugging and USB debugging are disabled.
Remove any suspicious apps you find. Go to Settings > Apps > See all apps, enable "Show system apps" if necessary, and locate recently installed or unknown apps. Force stop the suspicious app, clear its storage, and select Uninstall. Consider an app suspicious if it has a generic name, a blank icon, an odd installation date, or was installed outside the Google Play Store.
Restart normally after removal, then re-check Accessibility, Device Admin apps, VPN settings, and Developer options. Also check the list of installed applications for a second suspicious package, since the reported campaign uses a dropper to decrypt and install its malicious content.
mundophone
