ToxicPanda 2.0: Android Banking Malware Now Targets 140+ Apps and Steals PINs

A revamped ToxicPanda carries 167 remote commands and a PIN-grabbing routine aimed at more than 140 banking and cryptocurrency apps worldwide.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A smartphone screen displaying banking and cryptocurrency apps on the home screen, with malware infection indicators and PIN entry fields compromised by overlay
Share

Key points

  • Zimperium zLabs reported on Wednesday that ToxicPanda, also tracked as TgToxic, has returned in a heavily upgraded form.
  • The new build packs 167 remote commands, giving the criminals running it deep control over an infected phone.
  • It targets more than 140 banking and cryptocurrency apps, and now includes a workflow designed to harvest users' PIN codes.
  • The malware's reach has widened beyond its earlier Italy and Latin America focus into a broader global footprint.
  • Android users who sideload apps or grant Accessibility permissions to unfamiliar apps are the most exposed.

A piece of Android malware called ToxicPanda has come back with a serious upgrade, and it's aimed squarely at your banking app.

Researchers at Zimperium zLabs published findings on Wednesday describing what they call ToxicPanda 2.0, also known in the security industry as TgToxic. It's not a small tweak. The new version carries 167 separate remote commands: criminals controlling it can make an infected phone read a text message, tap a button, open an app, or approve a transfer, all without the owner realising.

What is ToxicPanda and what does it do?

ToxicPanda is banking malware for Android phones. Once installed, it hides in the background and waits for the user to open a banking or crypto app, then quietly takes over to steal money.

The malware belongs to the TgToxic family, first seen targeting users in Italy and parts of Latin America. The 2.0 version has widened its aim to victims around the world, according to Zimperium. It relies heavily on Android's Accessibility Services, a legitimate feature designed to help people with disabilities use their phones. When a malicious app is granted that permission, it can read what is on screen and tap buttons on the user's behalf. That's the mechanism almost every serious Android banking trojan, meaning malware disguised to steal banking credentials, depends on.

Zimperium's work on this family goes back further than Wednesday's report. When we covered Rokarolla, a separate Android trojan Zimperium catalogued in June, it carried 137 remote commands and a similar PIN-capture capability. ToxicPanda 2.0's 167-command set is a meaningful step beyond that.

Which apps are being targeted?

More than 140 banking and cryptocurrency apps are in the malware's target list, Zimperium said. The researchers didn't publish the full list, but the count tells you this isn't aimed at one country or one bank.

The standout addition is a PIN harvesting workflow. When a victim goes to approve a payment, the malware captures the PIN they type and sends it back to the attackers. Combined with remote control of the phone, a stolen PIN is often all that stands between the criminals and a cleaned-out account.

How does it end up on a phone?

Android banking trojans in this family typically arrive through sideloaded apps, meaning apps installed from outside the official Google Play Store, after a user is directed there by a phishing message or a fake ad. Once installed, the app asks for Accessibility permissions using a convincing pretext. Grant it, and the malware is effectively in charge.

Should you worry?

If you're on Android and you've ever installed an app from outside Google Play, yes. Check Accessibility settings now: Settings, then Accessibility, then Installed apps. Anything you don't recognise with permission there should come off immediately.

Stick to Google Play for installs. Turn on Google Play Protect if it isn't already active. Keep your banking app's biometric login on, and never type your banking PIN into a screen you weren't expecting to see. Transaction alerts from your bank are worth enabling: a text at the moment money moves is often the first sign something is wrong.

The PIN-theft angle is what makes this iteration worth paying attention to. Remote-access trojans are common enough. A workflow specifically built to lift the second factor that protects a payment raises the operational sophistication a notch, and that's the thing to watch as this variant spreads.

© 2026 Threat Vectr