ToxicPanda 2.0 Turns Wireless Debugging Into a Master Key for Android Banking Fraud

ToxicPanda Android Trojan https://www.pexels.com/photo/eating-panda-bear-14925845/

First discovered in late 2024 by cybersecurity company Cleafy, ToxicPanda has built up a known history in the past few years as an Android banking trojan with operations focused in Europe. Recently, Zimperium’s zLabs team identified a new variant of the malware with a dramatically expanded command set. This development significantly raises the stakes of ToxicPanda attacks, threatening the nexus of mobile banking, digital identity, and enterprise data on one device.

The Escalation by the Numbers

The evolution in ToxicPanda’s capabilities is illustrated in measurable enhancements to the scope of what it can do and where it can operate. From the previous version’s ability to target 16 banking applications, the newer variant can target nearly 350 apps across the Americas, Asia, and Africa. The newer version also demonstrates a major expansion from a limited command capability to a much more comprehensive set of remote commands. Even previously dormant commands from earlier versions of ToxicPanda are now fully operational in the new version.

“The 167-command set and 349 targeted apps across 16 countries also point to a fraud platform, not a one-off trojan. Operators can update targets, adapt to different Android vendors, and use AWS-hosted storage to distribute malware at scale,” says Jason Soroko, Senior Fellow at Sectigo, a Scottsdale, Arizona-based provider of comprehensive certificate lifecycle management (CLM). “The lesson extends beyond banking. Phones now hold corporate access, identity credentials, wallets, and account recovery channels.”

Abuse of Legitimate Developer Tools

Android Debug Bridge (ADB) wireless debugging works through a pairing mechanism that eliminates the need for a wired USB connection for debugging. This mechanism requires the user to activate Developer Options as well as enable USB debugging and wireless debugging on the device through a process involving seven consecutive taps on a particular field within device settings. After the correct settings are enabled, the pairing can take place.

The new version of ToxicPanda has demonstrated the ability to manipulate this process for malicious ends. The malware automates a simulated tap sequence to silently enable Developer Options and wireless pairing, laying the groundwork for the subsequent steps of the attack. From here, privilege escalation helps the attacker achieve shell-level access without triggering any of the standard consent prompts, granting significant privileges on the target device.

Establishing a Presence and Locking Victims Out

The malware enables attackers to carry out a range of malicious activity on the target device. One capability identified through zLabs’ analysis is a screen overlay attack that mimics the native Android lock screen in order to harvest PINs and passwords. ToxicPanda also demonstrates a tactic that involves pushing a fake system update screen to stop the victim from operating the device and mask the background activity being carried out on the target device. Targeting banking and financial apps, the malware monitors application usage and harvests credentials.

As previously mentioned, certain commands were in development in previous versions of ToxicPanda but are now effective in action. One of these newly working features uses bypass logic built specifically for Android Original Equipment Manufacturer (OEM) environments to defeat manufacturer restrictions related to the device’s battery and auto-start processes.

Cloud Infrastructure as a Delivery Vehicle

Another development of the newly discovered ToxicPanda variant is a shift away from the prior channels used for distribution of the malware and toward buckets hosted on Amazon Web Services (AWS). The use of cloud-hosted delivery tactics complicates the issues of detection and takedown of the malware attacks. Many organizations whitelist trusted cloud domains, a practice which has heavy implications if those enterprises are targeted by ToxicPanda.

In these cases, the attackers’ reliance on cloud distribution enables the malware to easily infiltrate target devices without being detected or blocked because the system is set to trust the source by default. Shane Barney, Chief Information Security Officer at Keeper Security, a Chicago-based provider of zero-trust and zero-knowledge cybersecurity software, notes that “by distributing through Amazon Web Services buckets, the operators make detection and takedown significantly harder because malware hosted on legitimate cloud infrastructure doesn't trigger the same alarms as a known malicious domain.”

What This Means for Enterprise Mobile Defense

The identification of this new strain of the ToxicPanda malware has far-reaching implications for organizations hoping to defend against such attacks. The new variant highlights where signature-based detection falls short against malware attacks abusing accessibility services native to the target device. Zimperium’s reporting on the evolution of the malware outlines a layered response including dropper detection, mitigation of cloud infrastructure and C2 risk, and behavioral telemetry. The broader picture presented by this discovery is the evolution of banking trojans into tools for persistent access, expanding their capabilities and operations significantly.

Author
  • Contributing Writer, Security Buzz
    PJ Bradley is a writer from southeast Michigan with a Bachelor's degree in history from Oakland University. She has a background in school-age care and experience tutoring college history students.