CiberLATAMbywhalemate

ToxicPanda 2.0 Targets 140 Banking Apps

Zimperium found ToxicPanda 2.0, an Android variant expanding to more than 140 banking and crypto apps across 16 countries.

Whalemate Labs · AI-assisted researchPublished:2 min read

Zimperium published an analysis on Aug. 19, 2026 of ToxicPanda 2.0, an Android banking trojan variant that broadens its potential reach to more than 140 banking and cryptocurrency apps across 16 countries. Mexico is among the markets with the largest presence on the list, alongside Pakistan, South Africa, Nigeria and India.

Zimperium published an analysis on Aug. 19, 2026 of ToxicPanda 2.0, an Android banking trojan variant that broadens its potential reach to more than 140 banking and cryptocurrency apps across 16 countries. Mexico is among the countries most represented on the list, while the impact is concentrated especially in Pakistan, South Africa, Mexico, Nigeria and India, according to the analysis cited by Infosecurity Magazine.

What changed in ToxicPanda 2.0?

Zimperium zLabs documented in August 2026 that the new version expands its overlay and remote-control capability to 349 financial institutions, banking apps, wallets and cryptocurrency apps in 16 countries. It also added a dedicated PIN theft mechanism aimed at more than 140 banking and crypto applications.

According to Security Affairs, ToxicPanda 2.0 uses Amazon AWS storage infrastructure to distribute malicious payloads and increased its remote command set to 167 instructions. Those functions include shell-level takeover capabilities and abuse of Android Wireless Debugging to strengthen access to the device.

Technical documentation summarized by Xpert4Cyber also says that some commands present in earlier versions were placeholders that had not been implemented, but in version 2.0 they are now fully functional. That significantly expands the operational reach of the malware operator behind it.

Where is the impact concentrated?

Independent analyses agree that ToxicPanda 2.0 is most heavily concentrated in Pakistan, South Africa, Mexico, Nigeria and India, where the highest density of financial apps appears in the list of overlay and credential theft targets.

Infosecurity Magazine said the targeted financial institutions span 16 countries, with Mexico among the most represented markets. The regional view places Latin America within the exposure map, at least because of Mexico's presence in the campaign and the type of apps reached by the variant.

How does it fit into the broader picture?

IBM X-Force reported in 2026 on activity by ITG27, a China-aligned group, and described campaigns observed against environments posing as an electric utility company and a state-level government agency. Although that attribution is outside Latin America, the case adds context on recent campaigns focused on espionage and persistent access in sensitive environments.

At the same time, tracking of ToxicPanda 2.0 shows a technical evolution marked by broader app coverage, more remote commands and distribution backed by cloud infrastructure, with Mexico among the countries identified by the research as one of the most visible focal points.

Sources

View all