ToxicPanda 2.0 Targets 349 Finance Apps Across 16 Countries
PYMNTS reported that ToxicPanda 2.0 now targets banking, wallet and cryptocurrency apps with 167 remote commands, extending an Android Trojan first tracked in 2024.

ToxicPanda 2.0 has expanded an Android banking-malware campaign across 349 banking, financial, digital wallet and cryptocurrency apps in 16 countries, PYMNTS reported, turning a memorably named Trojan into a broader mobile-fraud problem for financial institutions.
The current version gives attackers 167 remote commands after infection.
That control surface allows criminals to take over devices, steal financial credentials and initiate unauthorized transactions from phones that users may still regard as trusted banking channels.
Zimperium's zLabs mobile threat research team disclosed the new figures in an Aug. 19 release.
The target list links ordinary banking apps with wallets and cryptocurrency services, so the same mobile compromise can reach deposit accounts, payment credentials and digital-asset tools rather than a single financial application.
The malware family did not begin with the latest version.
Cleafy first encountered the original ToxicPanda in 2024 while examining code it initially treated as TgToxic, then separated it as a distinct family after finding enough technical differences.
That earlier investigation identified more than 1,500 infected devices and 16 targeted banks across Europe and Latin America, with evidence that suggested Chinese-speaking operators.
ToxicPanda's name also illustrates a security-operations problem that sits beside the technical one.
Malware labels can come from the company that first analyzes a family, the press shorthand that follows, or the naming rules used inside a security vendor.
The same code can collect several aliases before banks, analysts and defenders settle on a common reference.
Microsoft has acknowledged that confusion and uses the Computer Antivirus Research Organization naming structure to keep detections searchable by threat type, platform, family and variant.
A formal label such as Trojan:MSIL/Solorigate.BR!dha may be more precise than a branded animal name, but it is less likely to make a mobile-banking threat visible outside specialist teams.
The practical risk for banks and wallet operators is not the branding.
ToxicPanda 2.0 combines broad app targeting with remote device control, leaving institutions to detect fraudulent activity even when the transaction appears to originate from a customer's own Android phone.














