Ethical Hacking News
Recent updates on the ToxicPanda 2.0 and GoldDigger Android banking malware variants have revealed significant enhancements in their capabilities, including remote command execution, PIN harvesting, and privilege escalation. These malware variants have been found to target banking and cryptocurrency applications, resulting in a "massive infection" in South Africa and the U.K. Users are advised to review their installed applications, audit app permissions, and keep their devices up-to-date to stay safe against these threats.
Two malicious Android malware variants, ToxicPanda 2.0 and GoldDigger, have been identified as threats to Android device users. Both malware variants have sophisticated capabilities, including remote command execution, PIN harvesting, and privilege escalation. ToxicPanda 2.0 has a set of 167 remote commands, allowing it to abuse the Android accessibility service and steal UI elements on the screen. GoldDigger can inject input to banking apps to initiate fraudulent transactions and capture credentials entered on banking apps using fake overlays. It is advised to review installed applications, audit app permissions, download apps from trusted sources, keep devices up-to-date, enable two-factor authentication, and monitor bank accounts for unusual transactions to stay safe.
The cybersecurity landscape has been abuzz with the recent updates on two malicious Android malware variants, ToxicPanda 2.0 and GoldDigger, which have been wreaking havoc on Android banking apps and cryptocurrency exchanges, respectively. According to recent reports, both malware variants have been designed with sophisticated capabilities, including remote command execution, PIN harvesting, and privilege escalation, making them formidable threats to Android device users.
ToxicPanda 2.0, a variant of the infamous TgToxic malware, has been found to boast a significant enhancement in its capabilities, including a set of 167 remote commands, which allows it to abuse the Android accessibility service, steal every UI element on the screen, and overlay-based credential theft mechanism targeting over 140 banking and cryptocurrency applications. This new variant has been found to target more than 16 countries, demonstrating a global expansion in its targeting scope and capabilities.
The new version of ToxicPanda 2.0 also features an automated click-based mechanism to abuse Android Wireless Debugging via Android Debug Bridge (ADB) to facilitate privilege escalation and shell-level access on compromised devices. Additionally, it achieves this by using the accessibility services to enable Developer Options and turn on Wireless debugging.
According to security researcher Vishnu Pratapagiri, the malware connects to its command-and-control (C2) server by sending an initial HTTPS request to establish a bidirectional WebSocket communication channel to receive commands and exchange data. The malware can display full-screen "system update" overlays to conceal its background actions and deploy an invisible transparent overlay to capture touch and harvest PIN codes.
Another newly added functionality in ToxicPanda 2.0 is a prompt to trick the victim into granting Device Administrator privileges, overwriting the device's local lock screen PIN or password with an attacker-defined value, and profiling the infected device to determine the OEM vendor and take appropriate steps to exempt the malware from battery optimization policies using accessibility services and ensure uninterrupted background execution.
Meanwhile, the GoldDigger campaign, attributed to GoldFactory, a Chinese-speaking threat actor linked to other banking malware families targeting both Android and iOS, has been found to make use of a sophisticated packer called "dpt-shell" to obfuscate its code and resources in an attempt to resist analysis. The packer also implements a bevy of evasion techniques, including encrypting its native logic, detecting if Frida is attached to the process and, if so, crashing it, and preventing external debuggers from attaching by marking itself as being traced using the PTRACE system call.
The current GoldDigger campaign mainly impersonates airline companies and shopping retailers, resulting in a "massive infection" in South Africa and the U.K. Victims who end up installing these apps are asked to grant accessibility services permissions, which the malware abuses for fraudulent actions.
According to security researcher Shahar Tavor Lusky, GoldDigger can inject input to the banking app to mimic user interaction, such as entering text, clicking buttons, and performing gestures, which initiates fraudulent transactions from the victim's banking app to the attacker. GoldDigger can also give the operator real-time access to the victim's screen, capture credentials entered on banking apps using fake overlays, and run a targeted app within a virtual environment, giving the attacker full visibility into its runtime behavior and real-time interception of credentials and sensitive data.
To stay safe against these threats, it is advised to review installed applications and remove any unfamiliar or suspicious ones, audit app permissions before granting them, download apps only from trusted sources and developers, keep devices up-to-date, enable two-factor authentication (2FA) for all online accounts, and monitor bank accounts for unusual transactions.
Related Information:
https://www.ethicalhackingnews.com/articles/ToxicPanda-20-and-GoldDigger-Expand-Android-Banking-Attacks-with-On-Device-Fraud-ehn.shtml
https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html
Published: Thu Aug 20 07:45:01 2026 by llama3.2 3B Q4_K_M