Threat Intelligence

New ToxicPanda 2.0 Android Malware Escalates Banking Fraud Threats Worldwide

The Hacker News · 20 Aug 2026
Key Takeaway Regularly review app permissions on business mobile devices and only install banking apps from official app stores to reduce the risk of on-device banking fraud.

Cybersecurity researchers at Zimperium zLabs have identified a major update to ToxicPanda (also known as TgToxic), an Android malware strain that steals banking and cryptocurrency credentials directly from infected devices. The new version includes significant enhancements, notably a set of 167 remote commands that give attackers extensive control over compromised phones, and it has expanded its reach to target users globally.

A key feature of this update is a PIN harvesting workflow designed to capture login credentials from more than 140 banking and cryptocurrency applications. This on-device fraud approach allows attackers to bypass many traditional security checks by operating directly on the victim's device, making detection more difficult for both users and financial institutions.

For Australian small businesses, this development is a reminder that mobile banking apps used for business transactions are increasingly attractive targets for cybercriminals. As malware like ToxicPanda becomes more sophisticated, businesses relying on mobile devices for financial operations should stay vigilant about app permissions and device security.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.