Banks judge whether a transfer looks legitimate partly by where it comes from: the device, the network address, the app session, the way the account holder usually behaves. ToxicPanda 2.0 answers all of those questions correctly, because it is operating from the victim's own phone.
That is the entire point of it.
Fraud from the handset the bank trusts
Zimperium zLabs announced the new version on 19 August, describing an Android banking trojan and remote access tool built for account takeover and what the industry calls on-device fraud. Instead of logging in from an attacker's machine with stolen credentials, the operator drives the transaction from the compromised handset, inheriting its device fingerprint, its network location and its live app session in one go. Malwarebytes, which published its own write-up on 24 August, says the target list of banks and e-wallets is much larger than earlier ToxicPanda builds carried.
The capability set has widened with it: banking overlays, which are fake screens drawn on top of a real app to capture what you type, plus remote access, PIN capture, Android accessibility abuse and attempted automation of Wireless Debugging.
Accessibility is the whole game
Android's Accessibility Service exists so people who need help interacting with a screen can get it, which means an app granted the permission can inspect what is on screen, watch which app is in the foreground, act on the user's behalf and draw over other apps. Grant it to the wrong app and you have handed over the phone. Every recent Android banking family leans on it, including Rokarolla, which used overlays against roughly 200 apps.
The Wireless Debugging angle is the one to watch. It is a developer feature that lets another device issue commands over the network, and abusing it is the road RedHook took earlier this year. Here it is described as attempted automation rather than a settled capability, and that distinction is worth keeping.
The dropper cuts Google Play off first
Distribution has not changed. Victims are talked into sideloading the app rather than installing from Google Play, and the current campaign serves samples from Amazon AWS-hosted buckets. The dropper then runs a fake installation flow, asks for VPN privileges, uses them to block certain Google Play and Google Play Services network communications, decrypts an embedded payload, and finally requests Accessibility access for the payload it has just installed. Neither report spells out what the operators gain from the blocking, and it is not worth guessing at.
Getting it off an infected phone
A factory reset may end up being the answer, but Malwarebytes lists steps worth trying first. Put the phone in airplane mode and turn off Wi-Fi and Bluetooth to cut command and control traffic. From a second device, freeze or watch the accounts, revoke active sessions and reset banking credentials. Then start Android Safe Mode and work backwards: remove Accessibility access from anything unfamiliar, revoke Device Administrator rights (an app holding them can grey out the Uninstall button), delete VPN profiles you did not create, turn Developer options off entirely including Wireless and USB debugging, and only then uninstall the suspect apps. Check the app list twice, because the campaign uses a dropper that installs a second package. Menu paths vary by manufacturer and Android version.
Prevention is duller and works better: do not sideload apps from links in unsolicited messages, ads or supposed support communications, and treat any request for Accessibility, Device Administrator, developer settings or VPN permissions as a reason to stop and think. Malwarebytes detects the campaign as Android/Trojan.Dropper.agent and Android/Trojan.FakeApp.ACR2401245FC11, per its analysis; the underlying research is Zimperium zLabs'.
On-device fraud is the industry's answer to a decade of device fingerprinting, and it works by refusing to play the game at all. If the transaction never leaves the phone, there is no unfamiliar device to flag.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.