ToxicPanda 2.0: Android Banking Malware Now Targets 140+ Apps and Steals PINs

A revamped version of the ToxicPanda Android malware carries 167 remote commands and a PIN-grabbing routine aimed at banking and cryptocurrency apps worldwide.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial shot of an empty stadium tunnel at dusk leading toward a brightly lit pitch, shallow depth of field, slight haze, cool teal and warm so
Share

Key points

  • Zimperium zLabs reported on Wednesday that ToxicPanda, also tracked as TgToxic, has returned in a heavily upgraded form.
  • The new build packs 167 remote commands, giving the criminals running it deep control over an infected phone.
  • It targets more than 140 banking and cryptocurrency apps, and now includes a workflow designed to harvest users' PIN codes.
  • The malware's reach has widened beyond its earlier Italy and Latin America focus into a broader global footprint.
  • Android users who sideload apps or grant Accessibility permissions to unfamiliar apps are the most exposed.

A piece of Android malware called ToxicPanda has come back with a serious upgrade, and it is aimed squarely at your banking app.

Researchers at Zimperium zLabs published findings on Wednesday describing what they call ToxicPanda 2.0. The malware is also known in the security industry as TgToxic. The new version is not a small tweak. It carries 167 separate remote commands, meaning the criminals controlling it can make an infected phone do 167 different things on demand.

That range is what makes it dangerous. Read a text message. Tap a button. Open an app. Approve a transfer. All without the phone's owner realising.

What is ToxicPanda and what does it do?

ToxicPanda is banking malware for Android phones. Once installed, it hides in the background and waits for the user to open a banking or crypto app, then quietly takes over to steal money.

It belongs to a family known as TgToxic, first seen targeting users in Italy and parts of Latin America. The 2.0 version has widened its aim to victims around the world, according to Zimperium.

The malware relies heavily on Android's Accessibility Services, a legitimate feature designed to help people with disabilities use their phones. When a malicious app is granted Accessibility permission, it can read what is on screen and tap buttons on the user's behalf. That is the trick almost every serious Android banking trojan, meaning malware disguised to steal banking details, depends on.

Which apps are being targeted?

More than 140 banking and cryptocurrency apps are in the malware's target list, Zimperium said. The researchers did not publish the full list, but the count alone tells you the operation is not aimed at one country or one bank.

The standout new feature is a PIN harvesting workflow. In plain English: when the victim goes to unlock their banking app or approve a payment, the malware presents a fake screen or watches the real one, captures the PIN they type, and sends it back to the attackers. Combined with the malware's ability to control the phone remotely, a stolen PIN is often all that stands between the criminals and a cleaned-out account.

How does it end up on a phone?

Android banking trojans in this family usually arrive through sideloaded apps, meaning apps installed from outside the official Google Play Store, often after a user is directed there by a scam text, a fake ad, or a phishing message. The Hacker News noted the same distribution pattern in earlier TgToxic campaigns.

Once installed, the app asks for Accessibility permissions using a convincing pretext. Grant it, and the malware is effectively in charge.

What should Android users do?

Stick to Google Play for app installs. Treat any app that asks for Accessibility Services with real suspicion, especially if it is not a screen reader, keyboard, or password manager.

Check the Accessibility settings on your phone now: Settings, then Accessibility, then Installed apps. If something you do not recognise has permission, remove it.

Turn on Google Play Protect if it is not already active. Keep your banking app's own biometric login on, and never type your banking PIN into a screen you were not expecting to see. If your bank offers transaction alerts, switch them on. A text at the moment money moves is often the first sign something is wrong.

© 2026 Threat Vectr