
- VPN and Shell Access: ToxicPanda 2.0 abuses Android VPN permissions to intercept traffic and utilizes Wireless Debugging to gain shell access, bypassing standard permission prompts.
- Financial Targeting: The trojan targets 349 banking applications across 16 countries, with more than half of all infections occurring in Italy.
The Evolution of ToxicPanda 2.0
ToxicPanda 2.0 has emerged as an advanced evolution of a mobile banking trojan, with its presence first documented by Cleafy Labs in late 2024. This version marks a significant expansion in technical capability and targeting scope compared to its predecessors. Infrastructure analysis and specific code artifacts suggest that the threat actors behind the malware are likely Chinese-speaking individuals. The campaign has identified 349 specific financial and banking applications to target, focusing its operations on users across 16 different countries.
The distribution of the malware relies heavily on social engineering tactics. Potential victims are often manipulated into sideloading malicious files disguised as legitimate software, such as Google Chrome or Visa. By convincing users to bypass official security measures, the attackers establish a foothold on the device. This method of delivery highlights the risks associated with third-party installations, a topic often discussed in relation to Aptoide’s return to Google Play as a rival store. Once installed, the trojan begins its sequence of security deactivation and data interception.
Advanced Evasion via VPN and Wireless Debugging
A primary feature of the ToxicPanda 2.0 strain is its systematic abuse of Android VPN permissions. By requesting these permissions, the malware establishes a local tunnel that allows it to intercept and filter all device traffic. This capability is used to block access to the Google Play Store and Google Play Protect. By neutralizing these built-in security features, the trojan prevents the operating system from performing automated scanning or removing the malicious package. Similar network-based exploits have been seen in other sectors, such as Android car head units being infected with Pandora Proxy malware.
Furthermore, ToxicPanda 2.0 utilizes the Android Wireless Debugging feature to escalate its control over the hardware. By exploiting this feature, the malware gains shell access, which allows it to bypass the standard runtime permission prompts that usually require manual user approval. This high level of access enables the latest strain to support 167 remote commands. These commands are issued via a Command and Control (C2) server, giving attackers the ability to perform complex, automated tasks on the compromised device without the user’s knowledge.
On-Device Fraud and MFA Interception
The technical architecture of ToxicPanda is specifically designed to facilitate On-Device Fraud (ODF). This mechanism allows threat actors to initiate fraudulent transactions directly from the victim’s own device. By conducting the theft from the trusted hardware, the attackers can effectively bypass many identity verification systems and behavioral analytics used by banks. According to a technical analysis by Cleafy Labs, this method significantly increases the success rate of unauthorized transfers.
To ensure these transactions proceed without interruption, the malware is capable of stealing one-time passwords (OTPs). It achieves this by intercepting SMS messages and harvesting data from authenticator applications. Additionally, ToxicPanda exploits Android Accessibility Services to log keystrokes and capture sensitive data from the device interface. This comprehensive data collection ensures that even encrypted sessions can be compromised once the user interacts with the screen. As reported by SC Media, the expansion of the target list to hundreds of banking apps demonstrates the increasing scale of this operation. Currently, Italy remains the primary focus of the campaign, accounting for over 50% of the total infected device base.


