Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.”

Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account takeover, financial fraud, and longer-term device control.

The core objective is on-device fraud. That means that rather than logging in from an attacker-controlled machine, the operator can carry out actions from the victim’s infected phone, taking over the device, IP address, app session, and behavioral context that banks may use when deciding whether a transaction is fraudulent.

ToxicPanda 2.0 is built around abusing Android’s Accessibility Service, a legitimate feature intended to help people interact with their devices. When a victim grants this permission to a malicious app, the malware can inspect interface elements, observe app activity, automate interactions, and place deceptive content over legitimate apps, known as overlays.