SendTech Times
News
MARKET SIGNAL:

ToxicPanda 2.0 Targets 349 Finance Apps Across 16 Countries

Newsroom brief

PYMNTS reported that ToxicPanda 2.0 now targets banking, wallet and cryptocurrency apps with 167 remote commands, extending an Android Trojan first tracked in 2024.

Verified against source materialEdited by SendTech Times Fintech DeskSource: PYMNTS
ToxicPanda 2.0 Targets 349 Finance Apps Across 16 Countries
Image source: PYMNTS

ToxicPanda 2.0 has expanded an Android banking-malware campaign across 349 banking, financial, digital wallet and cryptocurrency apps in 16 countries, PYMNTS reported, turning a memorably named Trojan into a broader mobile-fraud problem for financial institutions.

The current version gives attackers 167 remote commands after infection.

That control surface allows criminals to take over devices, steal financial credentials and initiate unauthorized transactions from phones that users may still regard as trusted banking channels.

Zimperium's zLabs mobile threat research team disclosed the new figures in an Aug. 19 release.

The target list links ordinary banking apps with wallets and cryptocurrency services, so the same mobile compromise can reach deposit accounts, payment credentials and digital-asset tools rather than a single financial application.

The malware family did not begin with the latest version.

Cleafy first encountered the original ToxicPanda in 2024 while examining code it initially treated as TgToxic, then separated it as a distinct family after finding enough technical differences.

That earlier investigation identified more than 1,500 infected devices and 16 targeted banks across Europe and Latin America, with evidence that suggested Chinese-speaking operators.

ToxicPanda's name also illustrates a security-operations problem that sits beside the technical one.

Malware labels can come from the company that first analyzes a family, the press shorthand that follows, or the naming rules used inside a security vendor.

The same code can collect several aliases before banks, analysts and defenders settle on a common reference.

Microsoft has acknowledged that confusion and uses the Computer Antivirus Research Organization naming structure to keep detections searchable by threat type, platform, family and variant.

A formal label such as Trojan:MSIL/Solorigate.BR!dha may be more precise than a branded animal name, but it is less likely to make a mobile-banking threat visible outside specialist teams.

The practical risk for banks and wallet operators is not the branding.

ToxicPanda 2.0 combines broad app targeting with remote device control, leaving institutions to detect fraudulent activity even when the transaction appears to originate from a customer's own Android phone.

Share this article
inXf

Related articles

More
Keep Reading

More Stories

Latest
Saudi World Cup Contractor Hack Exposes 1.5 Million Files, Cyber Group SaysCybersecurityOct 7, 2026Saudi World Cup Contractor Hack Exposes 1.5 Million Files, Cyber Group SaysA cyber monitor identified a breach at a Saudi construction consortium linked to Jeddah Central Stadium, with about 17 terabytes of project and employee data reportedly stolen.Hamilton County Schools Starts K-12 Quantum Curriculum With TN QuantumWorksSportsOct 7, 2026Hamilton County Schools Starts K-12 Quantum Curriculum With TN QuantumWorksHamilton County Schools is using TN QuantumWorks curriculum from Chattanooga Quantum Collaborative and Thinking Media to introduce quantum concepts across grade levels as EPB adds a $22 million quantum computer.SUBCO Weighs Australia Cable Ship As Repair Capacity Shifts Toward 2030PoliticsOct 7, 2026SUBCO Weighs Australia Cable Ship As Repair Capacity Shifts Toward 2030SUBCO is considering an uncrewed survey vessel and a US$165 million cable-laying ship as Australia looks for more certain submarine cable survey and repair capacity beyond 2030.Nettle Raises $4.8 Million To Expand AI Insurance InspectionsReal EstateOct 7, 2026Nettle Raises $4.8 Million To Expand AI Insurance InspectionsIrish-founded Nettle raised a $4.8 million seed round led by MTech Capital to expand its AI insurance inspection platform across the US and Europe.Alliance Backs Kenya’s Cloud9 With $500,000 for Cross-Border PaymentsCapital & PolicyOct 7, 2026Alliance Backs Kenya’s Cloud9 With $500,000 for Cross-Border PaymentsAlliance invested $500,000 in Kenyan fintech Cloud9 as the company expands from digital banking into cross-border payments, stablecoin settlement and business accounts after two acquisitions.Googlebook Launch Leaves Samsung Phones Waiting For Better Together SupportDevices & Consumer TechOct 7, 2026Googlebook Launch Leaves Samsung Phones Waiting For Better Together SupportGooglebook laptops launched with Better Together phone features limited to Pixel devices, while Google says Samsung support for Android 17 phones will arrive in the coming weeks.AstaBrief Gives Asta An Open 8B Fast Mode For Scientific ReportsCapital & PolicyOct 7, 2026AstaBrief Gives Asta An Open 8B Fast Mode For Scientific ReportsAi2 released AstaBrief 8B as an open-weights report-generation model for Asta, with a one-pass pipeline that averaged 51.1 seconds per report in Fast mode.Atlassian Warns Data Centre Admins To Patch Critical File Access FlawCybersecurityOct 7, 2026Atlassian Warns Data Centre Admins To Patch Critical File Access FlawAtlassian is urging Data Centre customers to patch CVE-2026-21589, a critical flaw that can let unauthenticated attackers read specific web-root files.Finland Halts Work at Two Google Data-Centre SitesEconomyOct 7, 2026Finland Halts Work at Two Google Data-Centre SitesFinland’s environmental supervisor ordered preparatory work to stop at Google-linked data-centre sites in Muhos and Kajaani while Tuike Finland answers questions over forest clearance and environmental assessment requirements.FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchAIOct 7, 2026FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchStealth AI research startup FYDY is negotiating a $12 million maiden round from Lightspeed Venture Partners and General Catalyst as it builds OpenScientist and a frontier AI team split across India and the US.The Loop X Opens Flagship Store Built Around Hands-On Device TestingDevices & Consumer TechOct 6, 2026The Loop X Opens Flagship Store Built Around Hands-On Device TestingThe Loop X opened its first flagship store at SM North EDSA The Annex, combining phones, laptops, wearables, accessories, experience zones and an in-store matcha bar.Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.