ToxicPanda 2.0 Android Malware Uses VPN and ADB to Steal Banking Credentials
Zimperium zLabs published research on August 19, 2026, detailing ToxicPanda 2.0, an advanced Android banking malware distributed via AWS-hosted storage. The malware tricks users into granting VPN permissions, which it then uses to block Google Play and Google Play Services network traffic. It subsequently exploits Android's Accessibility Service to autonomously navigate device settings, enable Wireless Debugging, and pair with the local ADB daemon to gain shell-level privileges without rooting the device. Once active, the payload deploys fake overlay screens to harvest banking credentials, device PINs, and other sensitive data, while maintaining a persistent encrypted WebSocket connection to a command-and-control server. The malware supports 167 remote commands, enabling attackers to take screenshots, intercept SMS messages, simulate user input, and install additional APKs on compromised devices.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in