ToxicPanda
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-06-25 03:49:47
- Profile updated
- 2026-07-07 14:20:20
Targeted industries: financial-services
Context
ToxicPanda is an Android banking RAT first identified by Cleafy in October 2024. It shows similarity to the TgToxic campaign, but appears to be a new development rather than a derivative. The threat actors are likely Chinese speakers. ToxicPanda initially made use of hardcoded C2 domains only, but started to incorporate a DGA in late 2024.
Reports & references
- bitsight.com — Toxicpanda Android Banking Malware 2025 Study (report)
- malpedia.caad.fkie.fraunhofer.de — Apk.Toxic Panda (report)
- cleafy.com — Toxicpanda A New Banking Trojan From Asia Hit Europe And Latam (report)