New ToxicPanda 2.0 Android Malware Escalates Banking Fraud Threats Worldwide
Cybersecurity researchers at Zimperium zLabs have identified a major update to ToxicPanda (also known as TgToxic), an Android malware strain that steals banking and cryptocurrency credentials directly from infected devices. The new version includes significant enhancements, notably a set of 167 remote commands that give attackers extensive control over compromised phones, and it has expanded its reach to target users globally.
A key feature of this update is a PIN harvesting workflow designed to capture login credentials from more than 140 banking and cryptocurrency applications. This on-device fraud approach allows attackers to bypass many traditional security checks by operating directly on the victim's device, making detection more difficult for both users and financial institutions.
For Australian small businesses, this development is a reminder that mobile banking apps used for business transactions are increasingly attractive targets for cybercriminals. As malware like ToxicPanda becomes more sophisticated, businesses relying on mobile devices for financial operations should stay vigilant about app permissions and device security.