ToxicPanda 2.0 and GoldDigger Expand Android Banking Fraud
Researchers have identified a significantly enhanced version of the ToxicPanda Android banking trojan, also known as TgToxic, with 167 remote commands and expanded global targeting. According to Zimperium zLabs, the malware can harvest credentials from more than 140 banking and cryptocurrency applications through Android accessibility services. Its overlay attacks now target 349 financial institutions across 16 countries, up from just 16 banking applications in the previous version.
ToxicPanda 2.0 can display a deceptive full-screen system-update prompt while covertly executing commands in the background, alongside an invisible overlay that captures touch input and collects device PINs. It can also trick users into enabling Device Administrator, replace the local lock-screen PIN or password, identify the device manufacturer, and use accessibility controls to evade battery-optimization restrictions. To obtain shell-level access, the malware enables Developer Options and Wireless Debugging before automating interactions with Android Debug Bridge.
The malware establishes command-and-control communications through an initial HTTPS request followed by a bidirectional WebSocket channel. Zimperium also reported that recent ToxicPanda 2.0 samples were distributed through Amazon Web Services-hosted storage buckets, demonstrating the attackers’ use of legitimate cloud infrastructure for malware delivery. Similar to the Manic Android trojan, ToxicPanda relies on accessibility services and deceptive overlays rather than exploiting a single device vulnerability.
Separately, IBM Trusteer identified a GoldDigger campaign targeting organizations and customers in South Africa and the United Kingdom. GoldDigger, attributed to the China-linked GoldFactory group, is an on-device banking trojan associated with families including GoldPickaxe, GoldDiggerPlus, and GoldKefu. Its continued use of sophisticated packing and overlay-based techniques underscores the growing emphasis on device takeover and real-time transaction fraud. Android users can review potentially exposed credentials with the password checker, check known account compromises with the email breach checker, and review device privacy settings with the privacy checkup.