Published on August 24, 2026

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud


Severity

Medium

Detail

Cybersecurity researchers have identified an updated version of ToxicPanda (TgToxic), an Android banking trojan with significantly expanded capabilities. The new variant contains 167 remote commands and has broadened its financial targeting to more than 140 banking and cryptocurrency applications, with overlay-based credential theft targeting 349 financial institutions across 16 countries.

The malware also introduces PIN harvesting, device administration abuse, and automated interaction with Android Wireless Debugging. Separately, researchers have observed a new GoldDigger campaign targeting users in South Africa and the U.K., using Android Accessibility Services to steal credentials and conduct fraudulent transactions directly from victims’ banking applications.

How?

The attack begins when victims are tricked into installing malicious Android applications. ToxicPanda 2.0 has been distributed using AWS-hosted infrastructure, while the newer GoldDigger campaign disguises its applications as legitimate airline and shopping applications. After installation, both malware families rely heavily on social engineering to convince victims to grant Accessibility Services permissions. Once enabled, this legitimate Android feature becomes a powerful mechanism for the malware to observe screen content and interact with other applications.

ToxicPanda uses Accessibility Services to monitor UI elements and identify information displayed within targeted banking and cryptocurrency applications. It can place fraudulent overlays over legitimate applications to capture authentication information and uses a separate workflow to harvest PINs. A transparent overlay can also monitor touch activity while the malware hides its actions behind convincing full-screen system-update screens. This allows the malware to collect sensitive information while reducing the likelihood that the victim notices the malicious activity.

The updated malware also provides operators with 167 remote commands through a C2 connection. ToxicPanda initially contacts its C2 server through HTTPS before establishing a WebSocket channel for two-way communication. Through this channel, attackers can issue commands, collect information, and control different functions of the infected device. The malware can also profile the device’s manufacturer and modify battery-optimization settings so Android is less likely to restrict its background execution.

A more advanced feature allows ToxicPanda to abuse Accessibility Services to navigate Android settings and enable Developer Options and Wireless Debugging. This can provide the attacker with additional access through Android Debug Bridge (ADB). The malware can also attempt to obtain Device Administrator privileges and modify the device’s local lock-screen PIN or password, further increasing the attacker’s control over the compromised device.

GoldDigger follows a similar approach by using Accessibility Services to automate activity inside banking applications. It can simulate user input, including typing, clicking buttons, and performing gestures, allowing attackers to carry out fraudulent transactions from an active banking session. The malware can simultaneously use overlays to capture credentials and provide operators with real-time visibility of the victim’s screen.

GoldDigger also maintains communication with its C2 infrastructure through WebSockets and supports additional surveillance functions, including collecting SMS messages, contacts, location information, and input from applications. It can capture audio and video and stream the information to the attackers. Together, these capabilities allow the operators to steal authentication data while also manipulating the victim’s device and banking sessions.

Conclusion

ToxicPanda 2.0 and the latest GoldDigger campaign demonstrate the increasing use of Android Accessibility Services for banking fraud and remote device control. Instead of relying only on stolen credentials, these threats attempt to operate directly within legitimate banking applications and automate actions as if they were performed by the victim.

Users should avoid installing applications from untrusted sources and should carefully review requests for Accessibility Services, Device Administrator, or other sensitive permissions. Organizations should monitor for suspicious applications requesting excessive privileges, while users should keep Android devices updated and enable transaction notifications to identify unauthorized banking activity quickly.

Source

https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html