ToxicPanda

Malware type
rat
Family
Malware family
Last IoC activity
2026-06-25 03:49:47
Profile updated
2026-07-07 14:20:20

Targeted industries: financial-services

Context

ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024. It shows similarity to the TgToxic campaign, but appears to be a new development rather than a derivative. The threat actors are likely Chinese speakers. ToxicPanda initially made use of hardcoded C2 domains only, but started to incorporate a DGA in late 2024.

Reports & references

  • bitsight.com — Toxicpanda Android Banking Malware 2025 Study (report)
  • malpedia.caad.fkie.fraunhofer.de — Apk.Toxic Panda (report)
  • cleafy.com — Toxicpanda A New Banking Trojan From Asia Hit Europe And Latam (report)

External references