ToxicPanda 2.0 Turns Android Permissions Into Persistence

Zimperium’s zLabs said on August 19 that ToxicPanda 2.0 now targets 140+ banking and crypto apps and 349 financial institutions, up from 16 apps in the first wave. The Android banking Trojan is also adding new ways to keep control of a device after it lands. When a victim opens a target app, the malware fetches a fake overlay from its command server so passwords or PINs go into the attacker’s window. Zimperium says it also abuses Android Accessibility Service to reach wireless debugging and shell access, then uses that path to bypass runtime prompts, enable components, and steal device lock credentials for persistent access. For organizations that allow sideloading, accessibility-based assistive tools, or managed Android devices with developer options in play, the exposure is in the platform grants themselves as much as in any banking app. That makes this a policy-and-control problem, not something a patch to the app store or the bank can erase.

Part of the PlainSec briefing for 2026-08-21

Editions

Sources