Threat Intelligence

ToxicPanda Banking Trojan Evolves, Expanding Beyond Personal Finance Apps

Dark Reading · 25 Aug 2026
Key Takeaway Ensure employee mobile devices used for work have security software installed and only allow apps from official, trusted app stores.

Security researchers have identified a more advanced version of ToxicPanda, an Android-based banking trojan that has been steadily growing in sophistication. The latest variant includes new capabilities that extend its reach across additional regions and target a wider range of applications beyond traditional banking apps, signalling a shift toward broader enterprise risk.

While ToxicPanda originally focused on stealing banking credentials from individual users, its evolution suggests attackers are looking to maximise value from infected devices by targeting other sensitive data and accounts. This kind of malware typically spreads through malicious apps or links, tricking users into granting extensive permissions that allow attackers to monitor activity, intercept data, and control the device remotely.

For Australian small businesses, the growing sophistication of mobile malware like ToxicPanda is a reminder that employee smartphones and tablets used for work purposes are just as much a target as office computers. As these threats expand beyond banking apps, the potential for business email, cloud services, and internal systems to be compromised through a single infected device increases significantly.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.