ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
AI-summarised brief · reviewed before publication
Cybersecurity researchers revealed ToxicPanda 2.0, an upgraded Android banking trojan with 167 remote commands and expanded reach to 140+ banking and crypto apps across 16 countries. It abuses accessibility services to harvest PINs, hijack lock screens, and elevate privileges via ADB. The malware now uses cloud-hosted buckets for distribution and establishes a WebSocket C2 channel. Additionally, GoldDigger, linked to GoldFactory, employs a sophisticated packer and impersonates airlines and retailers, injecting fraudulent transactions and capturing credentials through fake overlays.
💡 Why It Matters
- · The dual rise of ToxicPanda 2.0 and GoldDigger underscores a strategic shift toward cloud-based delivery and sophisticated on-device fraud, enabling attackers to bypass traditional security layers and execute real-time credential theft at scale.