Mark RadarMARK RADAR
About
EN
Sign in
Event File FINTECH

ToxicPanda 2.0 Targets 349 Financial Apps Worldwide

2 reports · First detected 2026-08-25 · Last active 2026-08-29

ToxicPanda is an Android banking trojan designed to steal credentials used for mobile banking and digital wallets. The malware abuses Android Accessibility Services and wireless debugging to gain elevated control over infected devices. That access allows attackers to monitor user activity and place fraudulent screens over legitimate applications, capturing account names, passwords and PIN codes as victims attempt to sign in or authorize financial transactions.

Mobile security researchers have disclosed ToxicPanda 2.0, an expanded version targeting 349 banking, financial-services and electronic-wallet applications across 16 countries. The latest variant broadens the malware’s target list and strengthens its ability to control compromised devices. Users who grant accessibility or wireless-debugging permissions to applications from untrusted sources risk having login credentials and PINs intercepted in real time through counterfeit interfaces.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)