HomeSecurityAndroid banking trojans: ToxicPanda 2.0 and GoldDigger expand their attacks

Android banking trojans: ToxicPanda 2.0 and GoldDigger expand their attacks

ToxicPanda 2.0, the updated version of the notorious Android banking trojan, is back, more dangerous than ever, now targeting 349 financial apps in 16 countries — a dramatic increase from just 16 apps targeted by the previous version. Meanwhile, GoldDigger, another Android banking trojan, is expanding its operations with sophisticated on-device fraud techniques, threatening users primarily in South Africa and the United Kingdom. Cybersecurity researchers from Zimperium zLabs and IBM Trusteer reveal new capabilities of these threats, which leverage Android accessibility services to execute fraud directly from the victim’s device.

ToxicPanda 2.0 Android banking trojan attacks banking apps

ToxicPanda (also known as TgToxic ) has been active since at least July 2022 , but the new version represents a quantum leap in its capabilities. According to security researcher Vishnu Pratapagiri of Zimperium, ToxicPanda 2.0 now has 167 remote commands , a comprehensive PIN spoofing system targeting over 140 banking and crypto apps , and an automated click mechanism to abuse Android Wireless Debugging via Android Debug Bridge (ADB) . This allows attackers to gain shell-level access to compromised devices, significantly increasing the risk.

The broader landscape of Android banking trojans remains extremely competitive. Kaspersky reported 93,574 mobile banking trojan packages in Q2 2026 alone, a number that demonstrates how active and dangerous this threat category remains. Other malware such as Octagon and WindRelay (NFC relay malware) are following the same trend: the goal is no longer just to steal credentials, but to commit financial fraud in real time, directly from the victim’s device.

See also: ToxicPanda: New Android banking trojan allows fraudulent banking transactions

ToxicPanda 2.0: Technical details and new features

ToxicPanda 2.0 connects to C2 server via an initial HTTPS request, which establishes a two-way WebSocket for receiving commands and exchanging data. Similar to the recently discovered Manic malware, ToxicPanda 2.0 can display full-screen overlays for a supposed “system update” to hide its actions in the background, while also deploying an invisible transparent overlay to record keystrokes and intercept PIN codes.

Among the new features of ToxicPanda 2.0 are: prompting for Device Administrator, replacing the local PIN or screen lock code with a value set by the attacker, and profiling the infected device to identify the OEM. This allows the malware to exempt itself from battery optimization policies via accessibility services, ensuring uninterrupted execution in the background. Zimperium also noted that the new campaign uses Amazon AWS-hosted buckets to distribute the malware, suggesting that the attackers are leveraging cloud infrastructure to improve the resilience and efficiency of their distribution.

ToxicPanda 2.0 - SecNews.gr

Abuse of Android accessibility services is at the core of ToxicPanda 2.0. Through these, the malware can read every element of the user interface on the screen, steal credentials, and automate keystrokes and data entries on the infected device. In addition, it enables Developer Options and Wireless Debugging via accessibility services, allowing privilege escalation and shell-level access — a technique that was not available in previous versions of ToxicPanda.

GoldDigger: On-Device Fraud with Advanced Detection Evasion Techniques

GoldDigger is a distinct Android banking trojan that was first documented by Group-IB in October 2023.It is attributed to the GoldFactory, a Chinese-speaking threat actor associated with other banking malware targeting both Android and iOS, such as GoldPickaxe, GoldDiggerPlus , and GoldKefu. According to IBM Trusteer, GoldDigger uses a sophisticated packer called “dpt-shell” to hide its code and resources, resisting analysis by security researchers.

See also: GoldDigger Android Trojan empties bank accounts

The dpt-shell packer implements several detection evasion techniques: it encrypts its native logic, detects if Frida (a popular dynamic analysis tool) is attached to the process and terminates it, and prevents external debuggers from attaching by marking itself as "traced" via the PTRACE. The current GoldDigger campaign mainly imitates airlines and retail stores, resulting in a significant rate of infections in South Africa and the United Kingdom.

Google Play competing app stores court order Android

security researcher Shahar Tavor Lusky explained that GoldDigger can inject data into the banking app to mimic user interaction — typing text, clicking buttons, performing gestures — and thereby initiate fraudulent transactions from the banking app to the attacker. In addition, GoldDigger can provide the operator with real-time access to the victim’s screen, essentially turning it into a full-fledged Android RAT (Remote Access Trojan).

How to protect yourself from ToxicPanda 2.0 and GoldDigger

Addressing these threats requires a comprehensive approach that combines technical measures and user education. First and foremost, users and organizations should limit or block the installation of applications from unknown sources. Monitoring applications that request accessibility services — especially when there is no obvious reason — is critical for early detection of suspicious activity.

Using Mobile Threat Defense (MTD) that can detect overlays, screen scraping, device tampering, and malicious on-device accessibility behavior is a key line of defense. Additionally, requiring phishing-resistant MFA and transaction signing for banking workflows is essential, as stolen PINs and overlays can bypass weaker controls. Users should also be educated to avoid apps airline, retail, and bank, and verify the identity of the issuer before each installation. According to The Hacker News, monitoring for abnormal WebSocket and HTTPS on untrusted infrastructure — particularly cloud-hosted delivery points — can also help detect infections early.

See also: NFCShare: New Android malware turns banking apps into a trap

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Aptoide app store available on Google Play Store in the US

Overall, ToxicPanda 2.0 and GoldDigger represent a clear evolutionary trend in the world of Android banking trojans : from simple credential theft to full-blown automated on-device fraud. The expansion of ToxicPanda 2.0 ’s targeting from 16 to 349 financial apps , combined with GoldDigger ’s advanced evasion techniques , makes these threats particularly serious for users and organizations worldwide. Understanding their technical methods and adopting appropriate defensive measures is now imperative for every Android user using mobile banking apps.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS