Skip to Content

Banking Trojan Targets 140+ Apps on Executive Phones

A new ToxicPanda variant expands its target list across banking and crypto apps, showing why the device that approves payments is now part of the corporate perimeter.
August 21, 2026 by
Banking Trojan Targets 140+ Apps on Executive Phones

A banking trojan with more than 140 apps on its radar

Researchers at Zimperium have detailed a new version of the Android banking trojan known as ToxicPanda, identified as 2.0, capable of targeting more than 140 banking and cryptocurrency apps, according to a report by Infosecurity Magazine. A banking trojan (malicious software that disguises itself as a legitimate app to steal access to financial accounts) is a category that has been known for years, and what stands out in this analysis is the breadth of the target list combined with the way the threat behaves inside the device.

According to the publication, the malware abuses the system's accessibility features, those created to support people with disabilities, and allows the remote operator to interact with the screen as if they were the user. Because the actions originate from an already authenticated session, traditional antifraud checks and codes sent by SMS lose part of their effectiveness.

That leaves a direct question for decision-makers: how many devices with access to your company's online banking are, right now, outside any corporate security policy?

What this news means for your operation

In companies with 5 to 5,000 employees, corporate banking access rarely lives on a well-protected server, because it usually lives in a pocket, on a partner's cell phone, on the device of whoever handles finance, or on the phone of the director who authorizes transfers. These devices tend to be personal, they mix work and family apps, and in many cases they have never gone through any IT inventory.

Three gaps and three practical responses

The encouraging part of this story is that attacks of this type depend on very specific conditions, and each one of them has a mature countermeasure. The first gap is the unmanaged device, and it closes when you bring the devices that access financial systems into a formal policy, with an up-to-date inventory, a screen lock requirement, control over the installation of apps from unknown sources, and the ability to wipe data remotely in case of loss or suspicion.

The second gap is the absence of behavioral detection. EDR (Endpoint Detection and Response) extended to mobile devices observes app behavior, and not just the signature of already cataloged files, which makes it possible to flag unusual use of accessibility permissions or the installation of a package from outside the official stores before the first transaction. Combined with continuous proactive monitoring, this set shortens the distance between infection and response, something that a managed cybersecurity operation delivers in an integrated way.

The third gap is the weak second factor. MFA (Multi-Factor Authentication) based on an authenticator app or a physical security key replaces the SMS code, which can be read or redirected. Patch management keeps the operating system and apps up to date, and remote support makes it possible to isolate a suspicious device and reissue credentials in minutes, instead of days. To know where to start, a cybersecurity maturity assessment helps prioritize what delivers the fastest results.

If the cell phone that approves your company's payments were compromised, how long would it take for someone to notice?

For most organizations of this size, the honest answer is that the discovery would come only during bank reconciliation, when the money is already gone and the window to dispute it is tight. Fortunately, shortening that interval does not require a two-year project: an inventory of the devices that access financial systems, active EDR on those endpoints, MFA via an authenticator app or physical key, routine patch management, and continuous proactive monitoring form a package that is usually deployed in a few weeks.

It is worth adding to that a tested backup with validated restoration and a written response plan, because those who know exactly what to do in the first minutes preserve far more cash and credibility. Digital financial security comes from small decisions made in sequence, and each one of them makes your operation visibly more predictable.

Frequently asked questions

Can a banking trojan on a cell phone bypass the code sent by SMS?

Yes, in most cases. Malware of this type operates inside the already authenticated device and can intercept or read incoming messages, which reduces the effectiveness of SMS as a second factor. The practical recommendation is to migrate to multi-factor authentication with an authenticator app or a physical security key, which do not depend on the messaging network.

Do personal cell phones used to access the company's bank account need IT management?

Yes, whenever they access financial systems or corporate data. These devices can be brought into a security policy with inventory, mandatory screen lock, app installation control, and remote wipe, without interfering with personal use. A written usage agreement is what makes the model comfortable for both parties.

Which managed IT capabilities reduce the risk of corporate banking fraud?

The main ones are EDR extended to mobile endpoints, strong multi-factor authentication, routine patch management, continuous proactive monitoring, tested backups, and periodic training for finance teams. Added to process controls, such as dual approval of payments and audit trails, they address both the technical and the human side of fraud.

References

If you want to map which devices and financial access points in your operation are still uncovered, Zamak conducts a Strategic IT Assessment, No Strings Attached.

Banking Trojan Targets 140+ Apps on Executive Phones
August 21, 2026
Share this post
Tags
Archive