ToxicPanda 2.0 Tricks Users, Steals Bank Logins

Security Affairs · High sophistication
Last updated August 24, 2026

Zimperium reports ToxicPanda 2.0 is a mobile banking trojan that targets 349 financial apps across 16 countries by impersonating legitimate screens and prompts to trick users into granting permissions. After installation, it uses Android Accessibility and Wireless Debugging to gain deeper control of the phone and steal banking credentials and even the device lock-screen PIN/password.

How the Attack Worked

ToxicPanda 2.0 begins with deception rather than exploitation. The malware pretends to be a legitimate app and shows a fake installation screen that asks the victim to approve VPN permissions to "complete setup." Once granted, it uses that access to block Google Play Protect while quietly installing the real malicious payload hidden inside the app's files.

From there, the malware abuses Android's Accessibility Service to observe everything happening on the screen. It automates enabling Wireless Debugging and unlocking developer options, tapping the build number repeatedly without user involvement, to gain shell-level access and escalate its control over the device.

Why It Succeeded

The scheme works because each step looks like a normal part of using a phone. A fake installer screen resembles a routine permission request. Once the malware watches which app a victim opens, it matches it against a list of 349 targeted financial institutions and either overlays a fake login screen or deploys an invisible layer that captures every touch and PIN entry directly. Because the overlay closely mimics the real banking or crypto app, victims have little reason to suspect anything is wrong.

The malware goes a step further by overlaying a convincing fake version of the phone's own lock screen, allowing it to steal the device PIN, pattern, or password outright. Distribution through Amazon AWS-hosted buckets also complicates straightforward blocking efforts.

What to Watch For

  • Apps requesting VPN permissions during installation without a clear business reason
  • Unexpected prompts that don't match normal Play Store installation flows
  • Login screens in banking or crypto apps that look slightly different than usual
  • Repeated login prompts even after a successful sign-in
  • Lock screens appearing unexpectedly while actively using the phone
  • Settings changes, such as Developer Options or Wireless Debugging being enabled, without user action

How to Build Resistance

Treat unusual permission requests, particularly VPN and Accessibility Service prompts, as a stop-and-verify moment rather than something to approve just to finish an installation. Employees who use mobile banking or crypto apps should be encouraged to exit the app and contact the institution through a known-good method if they see sudden or repeated login prompts. Any unexpected lock screen behavior or unexplained settings changes, like Developer Options or Wireless Debugging being enabled, should be reported immediately since these can indicate a device takeover rather than a simple glitch. Building this habit of pausing before granting permissions is one of the most effective defenses against overlay-based credential theft like this.

Key findings

  • Targets expanded to '349 financial institutions across 16 countries' (up from 16 apps previously).
  • Initial install uses deception: it 'pretends to be a legitimate app' and shows a 'fake installation screen' to request VPN permissions.
  • Uses Accessibility Service to observe the screen and enable 'overlay-based credential theft' against targeted banking/crypto apps.
  • Automates enabling Android Wireless Debugging/ADB (including unlocking developer options) to gain 'shell-level access' and escalate privileges.
  • Can steal device unlock credentials by overlaying 'a convincing fake version of the phone’s own lock screen'.
  • Distribution shifted to 'Amazon AWS-hosted buckets', complicating straightforward blocking.

Who’s being targeted

  • Commonly targeted roles: All employees (Android users), Executives, Finance, IT/Helpdesk, Mobile/Endpoint Management (MDM) team.
  • Affected industries: Banking/Financial Services, Cryptocurrency/Fintech, Mobile/Consumer devices (Android users).
  • Attack channels: website.
  • Impersonated: Legitimate app installer / Android system installation flow, The victim’s bank/crypto app login screen, Android lock screen.

Red flags to watch for

  • App requests VPN permissions without a clear business reason
  • Unexpected prompts during installation that don’t match normal Play Store flows
  • Any app behavior that appears to disable or interfere with mobile security protections
  • Login screen appearance slightly different than usual (fonts/layout)
  • Repeated login prompts even after successful sign-in
  • App requests Accessibility permissions or behaves like it is “watching”/controlling the screen
  • Lock screen appears unexpectedly while actively using the phone
  • Unlock prompt repeats or behaves differently than normal
  • Phone shows signs of being controlled (settings toggled, developer options enabled) without user action
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is ToxicPanda 2.0?

ToxicPanda 2.0 is an Android banking trojan that targets 349 financial institutions across 16 countries by impersonating legitimate app screens and login prompts to trick users into granting permissions and revealing credentials.

How does ToxicPanda trick users into installing it?

It pretends to be a legitimate app and shows a fake installation screen that asks for VPN permissions, which it later uses to block Google Play Protect while secretly installing the real malware.

Can ToxicPanda steal a phone's lock screen PIN?

Yes, it can overlay a convincing fake version of the phone's own lock screen to capture the device PIN, pattern, or password directly.

What permissions should Android users be cautious about?

Users should treat unexpected requests for VPN permissions or Android Accessibility Service access as red flags, especially when they appear during app installation or normal use.

Read the video transcript

There’s a new mobile threat called ToxicPanda 2.0 that can steal your banking logins and even your phone’s unlock PIN. It starts as a normal-looking app from a website. During install, a fake setup screen suddenly demands VPN permission so it can 'finish', then quietly turns off Google Play Protect and hides the real malware inside. Here’s the nasty part: when you open your banking or crypto app, ToxicPanda uses Android Accessibility to watch the screen and drop a fake login over the real one, or even a fake lock screen, to capture every tap, password, and PIN. Your move: if any app asks for VPN or Accessibility during install and you’re not 100% sure why, stop right there, close it, don’t tap Allow, and report it to IT.

Similar attacks

Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Fake Airline Apps Push Android Banking Fraud

Fake Airline Apps Push Android Banking Fraud

Researchers report two Android banking malware families (ToxicPanda 2.0 and GoldDigger) that rely on tricking people into installing malicious apps and granting powerful permissions. GoldDigger campaigns impersonate airlines and shopping retailers and then abuse Android Accessibility to take over…

August 20, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
DEF CON Phish Uses Fake Coindesk VP + Google Doc

DEF CON Phish Uses Fake Coindesk VP + Google Doc

A real phishing campaign is targeting DEF CON speakers and attendees through X/Twitter messages pretending to be a Coindesk executive. Victims are sent to a Google document that attempts a “click-fix” trick to get them to paste malicious commands into a terminal or download malware. The goal is to…

August 21, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
DEF CON Attendees Hit With Fake CoinDesk DMs

DEF CON Attendees Hit With Fake CoinDesk DMs

After Black Hat/DEF CON, cybercriminals allegedly targeted conference attendees by impersonating a CoinDesk executive over X direct messages. Victims were pushed into a realistic workflow using Google Docs and a fake Dropbox DocSend installer to trick them into running malware on macOS or Windows.

August 21, 2026