FF News — The Fintech News Network

Zimperium Uncovers ToxicPanda 2.0 Targeting 349 Banking and Crypto Apps Globally

By Lauren Towner · 20 August 2026

Press Release: Zimperium Uncovers ToxicPanda 2.0 Targeting 349 Banking and Crypto Apps Globally | Featured Image by FF News

Mobile security leader Zimperium has identified a significant escalation in the Android threat landscape with the emergence of ToxicPanda 2.0. For fintech professionals, this represents a critical shift in risk profile, as the malware now targets 349 financial applications across 16 countries, utilizing 167 remote commands to automate device compromise and credential theft.

What was announced

Zimperium’s zLabs threat research team has detailed the evolution of ToxicPanda 2.0, an advanced Android banking trojan that marks a substantial upgrade from its predecessor. This latest variant is not merely a credential stealer; it is a comprehensive tool for financial fraud that significantly expands the scale and technical depth of its campaigns. The malware now supports 167 remote commands, allowing attackers to exert granular control over infected devices.

The scope of the threat has widened geographically and sectorally. ToxicPanda 2.0 has expanded its reach from a small selection of banking apps to 349 banking, financial, e-wallet, and cryptocurrency applications. These targets span 16 different countries, signaling a globalized approach to mobile fraud. Technically, the trojan employs sophisticated methods to maintain long-term persistence on Android devices, harvesting credentials and abusing legitimate operating system features to bypass standard security measures. As mobile adoption for digital identities and sensitive corporate data accelerates, the ability of this malware to automate device compromise poses a direct threat to the integrity of mobile-first financial services.

"ToxicPanda 2.0 demonstrates how quickly mobile malware continues to evolve. Rather than simply stealing credentials, this malware automates device compromise, expands financial targeting on a global scale, and abuses legitimate Android features to gain control over infected devices. It reflects the increasing sophistication of modern mobile threats."

Nico Chiaraviglio, Chief Scientist at Zimperium zLabs.

The companies involved

Zimperium is a prominent player in the mobile security sector, positioning itself as a global leader in AI-empowered protection. The company focuses on securing the mobile ecosystem, which includes mobile devices, applications, and the data they carry. Its research arm, zLabs, is dedicated to identifying emerging threats and vulnerabilities within the Android and iOS platforms, often uncovering sophisticated malware campaigns before they reach critical mass.

The firm provides on-device security solutions designed to protect organizations by detecting malicious application behavior, phishing overlays, and device compromises in real-time. In a market where mobile devices are increasingly used as the primary interface for both consumer banking and enterprise access, Zimperium operates at the intersection of cybersecurity and financial services. By focusing on AI-driven detection, the company aims to mitigate risks such as those posed by ToxicPanda 2.0, which rely on evading traditional signature-based security measures through automated and adaptive techniques.

What FF News has reported before

FF News has closely followed Zimperium’s ongoing efforts to track the rapid diversification of mobile threats. In March 2026, we covered a New Zimperium Report Finds Banking Malware Expands Global Reach, Targeting 1,200+ Financial Apps, which highlighted the massive scale of the current threat environment. This followed a specific regional alert where Zimperium zLabs Uncovers PixRevolution Android Trojan Hijacking Brazil’s PIX Payments in Real Time.

Earlier reports also detailed the technical progression of these tools, such as when Zimperium Discovers New Hook Banking Trojan Variant With Most Advanced Capabilities to Date in 2025. Furthermore, the firm’s research into Sophisticated SMS Stealer Campaigns in 2024 demonstrated how mobile-targeted malware is increasingly used to infiltrate corporate networks.

What this means

The arrival of ToxicPanda 2.0 should serve as a wake-up call for financial institutions relying on mobile apps as their primary customer touchpoint. The jump to 167 remote commands indicates that malware authors are moving away from simple data harvesting toward full "Account Takeover" (ATO) automation. By abusing legitimate Android features, this trojan makes it harder for consumers to notice a compromise, placing the burden of detection entirely on the service provider. Banks and e-wallet providers are under increasing pressure to implement on-device threat detection, as traditional server-side fraud monitoring may be insufficient against malware that controls the device itself. Watch for a rise in similar "2.0" variants as attackers refine their automation playbooks.

Companies in this story: Zimperium

People in this story: Nico Chiaraviglio

More from News