ToxicPanda Android Malware Steals Banking PINs and Gains Shell Access
Key Takeaways A new variant of the ToxicPanda Android banking trojan, dubbed ToxicPanda 2.0, has been identified with expanded capabilities to steal banking PINs and gain shell access to infected...
Key Takeaways
- A new variant of the ToxicPanda Android banking trojan, dubbed ToxicPanda 2.0, has been identified with expanded capabilities to steal banking PINs and gain shell access to infected devices.
- The malware employs sophisticated social engineering tactics, including fake installation flows and login overlays for hundreds of financial institutions across 16 countries.
- ToxicPanda 2.0 leverages Android Wireless Debugging to achieve shell-level access without physical device interaction, granting attackers significant control.
- The threat actors distribute the malware via malicious files hosted on Amazon AWS and actively monitor and adapt their targets through remote commands.
- Users and organizations must exercise extreme caution with app installations and permission requests, and monitor for suspicious device activity to mitigate risk.
A sophisticated new iteration of the ToxicPanda Android banking trojan poses an escalated threat to mobile users. This updated malware, designated ToxicPanda 2.0, is engineered to exfiltrate banking PINs, mimic legitimate application interfaces, and achieve deep device control through the exploitation of developer-intended functionalities.
Table Of Content
ToxicPanda 2.0 demonstrates a significantly expanded targeting scope and an increased number of remote commands compared to its predecessors. Its distribution method involves malicious files stored in Amazon AWS buckets. Upon execution, it initiates a deceptive installation sequence designed to trick users into granting critical Android permissions.
Security researchers at Zimperium identified the updated malware, noting its arsenal includes 167 distinct remote commands. The campaign is capable of targeting over 140 banking and cryptocurrency applications for PIN theft. Furthermore, its convincing fake login screens now encompass 349 financial institutions operating in 16 different nations. The comprehensive capabilities of this malware are detailed in Zimperium’s detailed report.
The extensive capabilities of ToxicPanda allow it to persist and expand its malicious activities beyond mere credential theft. Once installed, the malware can monitor applications, extract on-screen data, capture user touch input, display fraudulent pages, and maintain persistent access to the compromised device. Previous iterations of ToxicPanda had already infected over 4,500 devices, primarily concentrated in Portugal and Spain.
Notably, this new variant leverages Android Wireless Debugging to achieve shell-level access, as Zimperium said in a report. This technique allows attackers to execute arbitrary commands and circumvent standard Android security measures without requiring physical access to the device.
ToxicPanda Android Malware
The infection process begins with a dropper application that presents a convincing fake installation interface, requesting VPN-related permissions. This initial step can enable the malware to disrupt connections to Google Play and Google Play Services, facilitating the decryption and installation of its hidden payload.
Accessibility permissions are fundamental to ToxicPanda’s operation. These permissions grant the malware the ability to monitor screen content and interact with the user interface. This method is a common characteristic of Android banking trojans that deploy fake sign-in windows to harvest account credentials.
Following successful installation, ToxicPanda enumerates all applications on the device, transmitting their package names and icons to its command-and-control (C2) server. When a user opens a targeted financial application, the C2 server can deliver a corresponding HTML overlay that meticulously replicates the legitimate login or payment screen.
The malware is also capable of deploying a transparent overlay over banking keypads to log the victim’s keystrokes. Its <replacePinTargets> command enables operators to dynamically update the list of applications and keywords used for PIN collection, allowing the attackers to pivot targets without distributing a new malicious application.
The abuse of Wireless Debugging is a particularly alarming feature. ToxicPanda automates screen interactions to enable Developer Options, activate Wireless Debugging, initiate the pairing process, and extract the temporary six-digit pairing code. It then establishes a connection with the local ADB service at 127.0.0.1, thereby gaining shell user privileges.
With shell-level access, the malware can attempt to self-grant additional permissions, bypass background restrictions, silently enable system components, and enhance its persistence on the device. This capability significantly elevates the threat beyond typical credential-stealing applications.
Overlays Hide Persistent Control
ToxicPanda also possesses the ability to steal device-unlock PINs, passwords, and patterns by presenting a deceptive Android lock screen. This overlay is meticulously designed to mirror the authentic lock screen, transforming a routine unlock attempt into an opportunity for credential harvesting.
In certain instances, the attackers employ a fake full-screen system update to mask their malicious activities. This social engineering tactic keeps users occupied while the malware modifies settings or waits for sensitive information, a strategy reminiscent of fake Google Play updates utilized by other Android banking threats.
The updated command set includes options to request Device Administrator privileges and forcibly reset the phone’s lock-screen password. Another command allows the malware to load an attacker-controlled web page in a full-screen WebView, providing an additional avenue for delivering phishing content or misleading prompts.
ToxicPanda actively works to circumvent Android’s power-management features. It identifies the device manufacturer and uses Accessibility Services to navigate vendor-specific auto-start and battery optimization settings, aiming to prevent the operating system from terminating its background processes. This exploitation of accessibility-driven device control has become a prevalent characteristic of modern Android banking malware.
What You Should Do
- Avoid installing APK files from untrusted sources, such as unsolicited links or unofficial app stores.
- Be highly suspicious of any application requesting unusual permissions like Accessibility Service, Device Administrator, VPN, Developer Options, or Wireless Debugging, especially if the app is not from a reputable developer.
- Regularly review the permissions granted to installed applications and revoke any that seem excessive or unnecessary.
- Organizations should monitor for abnormal Accessibility Service activity, automated changes to developer settings, suspicious overlay behavior, and unexpected ADB pairing events on employee devices.
- Promptly uninstall any unrecognized applications and regularly review enabled accessibility services to limit potential exposure and prevent the establishment of persistent control by malware.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 127.0.0.1 |
Local ADB daemon address used during ToxicPanda’s Wireless Debugging pairing process.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/deae1aae-5854-45ec-9448-12867d6661f1/ToxicPanda-Android-Malware-Can-Steal-Banking-PINs-and-Gain-Shell-Access-to-Phones.pdf?AWSAccessKeyId=ASIA2F3EMEYEX6FNCOG5&Signature=heG%2By3hz7DpPDdx4Ei9AGw3cF6w%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEMb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIDLCzv%2Bnd1NpDFEdzvQCuD0hoHqJaRQ1nNmhZZ8BYg06AiAok50BvHLZniGLZCVMphHO63Eaize1TUmrg1sd08mNTir8BAiO%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMJcjx4%2BTwgeku6RcEKtAEfWyoo2rZV6mkRijdgwYd18SIrZVgcn8ukY1YYS448%2BmzO4su7uDVPhlPO%2FFtUs%2FJqZWUHbY5e5vfshLmu%2Fp9XafEgnNSBzj9iIynhatqzgrT6sFdxphUOW38Pt7TU2cK3ybM9DA4OGCBPbwiaDELtrcTyUOFpUZZfytjbK3e226lNFdAipGF%2BYb48i8iMY%2Bq9accoumx2hPB2uE%2BCJNYGa3eICN%2Bi01pKsaJXt5dhM%2BhZ%2BvbB3ApdSFwBIN3jQECuWa4gX679A9P%2B898rrKXhNQgGhs%2FnFyfvUNjeBkp4QjxIyar8bl6tVTNL2%2FYY%2BxIeOgiIQcdM8wyKF0N4zh08KP%2BQ%2BZ7EfdvNyJQaybYHGiLSnYkN0DR%2BPki46nl3%2Bv2uTmgzrfjVRcg7Llbj%2FyaHfhDKSZCJLT3utxZFN2arBIdfu%2BUgzrh%2FCJU0bN4cgm8wMlC7dw1DieU64aagWamtRRYrPSPQdUGiA4uJkO4Rfpfk3j8oWCRc2hLnOMq3vdiCMVMrn8hdSKNshcNnAdyZ6Bu7buNj5zZQUUOvxepOc%2BEEVov%2BJWHeyCHAHInFV3pyK9TaK8Ok%2BLb2QQLw9gSP3RThzeIxKjv7XxWIUH%2BCoCBA8D2PD
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.