ToxicPanda Android malware expands to 349 apps, 167 commands
This digest was compiled by AI from multiple sources — links to the originals are below.

ToxicPanda Android malware has evolved to target 349 applications and support 167 remote commands, according to mobile security firm Zimperium. The malware now requests VPN permissions to block Google Play communications before installing its payload. It also automates Android Debug Bridge abuse to gain shell access on infected devices.
Key Facts
- ToxicPanda 2.0 targets 349 banking, financial, cryptocurrency, and e-wallet applications across 16 countries.
- The malware supports 167 remote commands and includes a PIN-harvesting module for 140 financial and cryptocurrency apps.
- ToxicPanda 2.0 is distributed through Amazon AWS-hosted buckets, according to Zimperium.
- The malware requests VPN service permissions to block communications from Google Play and Google Play Services.
- ToxicPanda automates Android Wireless Debugging Bridge (ADB) abuse to gain shell-level access on infected devices.
VPN Permission Abuse
ToxicPanda 2.0 requests VPN service permissions to create a local interface that controls network traffic. This enables the malware to block communication from Google Play and Google Play Services. Network-level control allows interference with app verifications, updates, and Play Protect communication. After obtaining VPN permissions, ToxicPanda blocks Google Play communications before extracting and installing its payload. The malware then requests Accessibility Service permissions to continue its attack chain.
ADB Automation
ToxicPanda 2.0 includes functions to automate the Android Wireless Debugging Bridge (ADB), enabling shell-level access. Using Accessibility Services, the malware enables Developer Options and activates Wireless Debugging. It extracts the six-digit ADB pairing code and port, then connects with the device's local ADB service. The 'autoBoot' command identifies the device manufacturer and launches OEM-specific auto-start settings to maintain persistence. This bypasses battery consumption protections on Xiaomi, OPPO, Vivo, Samsung, and Huawei devices.
Phishing and PIN Harvesting
ToxicPanda 2.0 uses phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications. The overlays are invisible to victims, allowing the malware to capture touch inputs on targeted apps. A separate PIN-harvesting module targets 140 financial and cryptocurrency apps and can dynamically update the target list. ToxicPanda spoofs the Android lock screen to capture device PINs, unlocking patterns, and passwords. Some analyzed samples used fake system update screens to hide ongoing malicious activity.
2 sources
ToxicPanda Android malware expands to 349 apps, 167 commands



