Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » ToxicPanda 2.0 and GoldDigger Expand Global Android Banking Attacks Through On-Device Fraud

ToxicPanda 2.0 and GoldDigger Expand Global Android Banking Attacks Through On-Device Fraud

By:
Last updated:August 20, 2026
Human Written
  • ToxicPanda 2.0 expands its targeting to 349 financial applications across 16 countries, abusing Wireless Debugging and Accessibility Services for full system control.

  • GoldDigger targets users in South Africa and the U.K. using the dot-shell packer to evade detection while executing automated on-device financial fraud.

  • Mobile users can defend against these advanced trojans by avoiding third-party application downloads, auditing Accessibility permissions, and enabling multi-factor authentication.

ToxicPanda 2.0 Targets 349 Banking Apps as Android Fraud Threats Spread

There has been a rise in sophisticated Android banking trojan malware worldwide, threatening mobile banking systems. Security experts at Zimperium zLabs discovered an upgraded version of the ToxicPanda virus, dubbed TgToxic. The malware is capable of executing 167 commands remotely and has expanded its targeting to a global level.

At the same time, a group of researchers from IBM Trusteer noted that the number of GoldDigger attacks has increased rapidly in South Africa and the UK. Both types of viruses work by applying sophisticated methods to launch fraud on mobile phones and allow cybercriminals to control infected devices. Also, they can drain user accounts without triggering standard anti-fraud alerts.

ToxicPanda 2.0 Escalates Global Reach and System Control

The updated ToxicPanda 2.0 variant represents a massive technical evolution from its original release four years ago. Security researcher Vishnu Pratapagiri noted that the latest iteration expands its credential theft operations to target 349 financial institutions across 16 countries. But the previous version targeted only 16 banking applications.

To establish persistent communication with external command servers, the malware initiates an initial HTTPS request. This move helps it to create a bidirectional WebSocket channel of communication. This persistent network connection allows remote operators to issue instructions instantly. They can also harvest personal identification numbers and exfiltrate screen data from compromised devices.

Furthermore, the malware introduces an automated mechanism to abuse Android Wireless Debugging through the Android Debug Bridge interface. By leveraging Accessibility Service privileges, the software autonomously toggles Developer Options and enables Wireless Debugging to grant attackers elevated shell-level permissions.

The updated strain also displays fake full-screen system update interfaces to disguise background operations while placing transparent overlays over legitimate apps. These invisible touch-capturing layers record physical tap coordinates. Thus, they allow attackers to harvest personal identification numbers and personal lock screen passcodes effortlessly.

To ensure uninterrupted execution, the software profiles the host system to identify the original equipment manufacturer vendor. It then abuses Accessibility Service options to exempt itself from aggressive battery optimization policies. This happens after tricking users into approving Device Administrator privileges.

Additionally, researchers observed a distinct shift in distribution infrastructure, as attackers deliver ToxicPanda 2.0 payloads through Amazon AWS-hosted storage buckets. Utilizing commercial cloud platforms allows threat actors to scale payload delivery reliably while bypassing traditional domain blocking filters.

GoldDigger Deployment Deploys Advanced Evasion Techniques

The GoldDigger banking trojan has also resurfaced with updated packing technology and new geographic targets. This malware is operated by the Chinese-speaking threat group GoldFactory. Security teams at IBM Trusteer discovered that current campaigns heavily target users in South Africa and the United Kingdom. The attackers impersonate popular airline carriers and retail platforms.

To resist automated analysis, the malware employs a specialized commercial packer called dpt-shell that obfuscates underlying application resources and native executable logic. The packer actively monitors system processes to detect dynamic analysis tools like Frida. Also, it crashes the application instantly if anyone detects the monitoring hooks.

The program furthermore uses the PTRACE command to inform the operating system that it is monitored to stop other external debuggers from connecting to the running process. These anti-analysis techniques make it highly impossible for the automated sandbox systems to observe the internal mechanics of the malware.

After being downloaded onto the victim device, the app tricks the target into enabling Accessibility Service permissions. This allows it to use the gained access to send fake input commands and execute gestures inside the legitimate banking app. It can also perform other functions, such as pressing interactive buttons, typing in texts, and so on.

Therefore, the malicious software can perform unauthorized money transactions via the mobile application while imitating the behavior of real users. Shahar Tavor Lusky, an expert in security research, noted that with the use of this fraud mechanism, remote operators receive full control over active banking operations.

In addition to automated transaction injection, the software grants operators real-time screen visibility and captures login credentials using malicious web overlays. The malware can even execute targeted applications inside an isolated virtual environment to intercept sensitive session data during execution.

For command infrastructure, GoldDigger creates a WebSocket connection to receive instructions and collect contact records. The connection also allows it to intercept incoming SMS messages and capture live device audio and video. The program streams captured media back to remote servers using the Real-Time Messaging Protocol. At the same time, it opens specific web links and system applications on command.

Protecting Enterprise Networks and Mobile Financial Consumers

The integration of automated input infestation, transparent overlay controls and advanced concealment techniques indicates a progressive transition towards client-side mobile financial fraud. Banking Trojans can operate within legal user sessions, thus making standard server-side risk engines incapable of separating harmful transactions from authentic consumer activities.

The threat of state-sponsored cyberattacks is also a growing concern in critical infrastructure sectors. The FBI, CISA, and other U.S. government agencies have issued warnings about Iranian-affiliated hackers actively targeting internet-connected programmable logic controllers (PLCs) across water, energy, and manufacturing sectors, aiming to disrupt critical industrial processes.

To lessen risks from the newer Android threats, mobile users need to be extremely careful in handling application permissions and software downloads. Specifically, a user should avoid downloading packages from unknown sites, strange source-sharing platforms, or suspicious messages.

In addition, consumers should periodically check installed software and uninstall unknown applications immediately. Device owners should inspect requested application permissions carefully, ensuring that basic utility apps cannot access sensitive Accessibility Service options or Device Administrator rights.

Maintaining updated operating system software remains vital for patching known Android Debug Bridge vulnerabilities and interface exploits. Besides, all users should use multi-factor authentication to ensure extra obstacles against identity theft. This secures their banking and crypto accounts by adding extra protective layers

It is necessary for financial institutions and software developers to approve client-side threat protection tools that will identify early misuse. Also, such tools expose debug hooks and Accessibility Service abuse in real time.

Combining behavioral monitoring with strict application hygiene helps organizations defend consumer assets against sophisticated on-device fraud operations. Combatting modern mobile banking trojans requires continuous vigilance from both software platforms and individual mobile users.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.