ToxicPanda 2.0 can take over your Android phone and banking apps

Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.”

Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account takeover, financial fraud, and longer-term device control.

The core objective is on-device fraud. That means that rather than logging in from an attacker-controlled machine, the operator can carry out actions from the victim’s infected phone, taking over the device, IP address, app session, and behavioral context that banks may use when deciding whether a transaction is fraudulent.

ToxicPanda 2.0 is built around abusing Android’s Accessibility Service, a legitimate feature intended to help people interact with their devices. When a victim grants this permission to a malicious app, the malware can inspect interface elements, observe app activity, automate interactions, and place deceptive content over legitimate apps, known as overlays.

ToxicPanda has historically relied on social engineering to persuade users to sideload a malicious Android application rather than install it through Google Play. The latest campaign uses Amazon AWS-hosted buckets to deliver ToxicPanda 2.0 samples.

After installation, the dropper presents a fake installation flow, requests VPN privileges, blocks certain Google Play and Google Play Services network communications, decrypts an embedded payload, and then seeks Accessibility Service permission for the installed payload.

The consequences can include stolen banking usernames and passwords, intercepted or captured PINs, fraudulent transactions, loss of access to the device, and exposure of the phone’s screen-lock secret. An attacker that can operate inside an active banking session from the victim’s device may have a better chance of evading controls designed to identify unfamiliar devices or unusual login locations.

How to stay safe

However sophisticated it is, ToxicPanda 2.0 still relies heavily on social engineering to get targets to install the malicious app and give it the permissions it needs. So our main recommendations are:

  • Avoid sideloading apps, especially from links in unsolicited messages, ads, or alleged support communications.
  • Treat requests for Accessibility access, Device Administrator privileges, developer settings, and VPN permissions with particular caution, especially if it’s not clear why the app needs those permissions or if you don’t fully trust it.
  • Use an up-to-date, real-time anti-malware solution for your device that can detect and block the malicious payload. Malwarebytes for Android detects apps in the ToxicPanda 2.0 campaign as Android/Trojan.Dropper.agent and Android/Trojan.FakeApp.ACR2401245FC11.

If your device is infected

Although it may require a factory reset to regain control of an infected device, there are some things you can try first:

  • First, put the phone in airplane mode and turn off Wi-Fi and Bluetooth. This can cut off command-and-control communications and ongoing credential theft while you investigate.
  • Use another device to freeze or closely monitor transactions, revoke active sessions, and reset your banking credentials.
  • Do not interact with fake “system update” screens or unexpected prompts for Accessibility, VPN, Device Administrator, Developer Options, or Wireless Debugging.
  • Start Android Safe Mode. Google recommends Safe Mode to help identify problems caused by downloaded apps. Remove recently installed or suspicious apps one at a time, reboot normally, and see whether the problem returns.
  • Remove Accessibility access first. In Settings > Accessibility > Installed apps/Downloaded apps, disable any service you do not recognize. Focus on recently installed apps or anything pretending to be an update, system component, security tool, document viewer, or bank helper.
  • Next, check Device Administrator rights. Go to Security & privacy > More security settings > Device admin apps and disable any unrecognized administrator before attempting removal. An app with Device Administrator privileges can make the Uninstall control unavailable.
  • Then check your VPNs. Go to Settings > Network & internet > VPN or search Settings for “VPN,” and delete any VPN profile you did not deliberately install. The ToxicPanda dropper uses VPN permission as part of its reported Google Play and Google Play Services blocking process.
  • Disable dangerous developer functionality. Search Settings for Developer options, turn it off entirely, and make sure Wireless debugging and USB debugging are off.
  • Remove all the suspicious apps you found. Go to Settings > Apps > See all apps, enable Show system apps if necessary, then locate recently installed or unfamiliar apps. Force stop the suspicious app, clear its storage, and select Uninstall. If an app has a generic name, blank icon, odd install date, or was installed outside Google Play, treat it as suspicious.
  • Reboot normally after removal, then re-check Accessibility, Device Administrator, VPN, and Developer Options. Also review the installed-app list for a second suspicious package, since the reported campaign uses a dropper to decrypt and install its payload.

Please note: The given paths in Settings may differ depending on your device manufacturer or Android version.

If you’re having trouble removing ToxicPanda manually and you can’t install or update Malwarebytes, please reach out to our Support team. They can walk you through the process.

Scammers know more about you than you think.

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.

Download for iOS → Download for Android →

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论