ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks
Cybersecurity researchers have discovered updates to the ToxicPanda and GoldDigger Android malware, which now have enhanced capabilities to steal banking and cryptocurrency credentials

The Android malware landscape has become increasingly complex with the emergence of updated versions of ToxicPanda and GoldDigger. According to Zimperium zLabs, the new version of ToxicPanda, also known as TgToxic, features significant enhancements, including a set of 167 remote commands. This malware has been active in the wild since at least July 2022 and has expanded its targeting footprint globally.
## ToxicPanda 2.0 Capabilities ToxicPanda 2.0 is known to abuse the Android accessibility service to steal UI elements on the screen and uses an overlay-based credential theft mechanism. The latest iteration targets 349 financial institutions across 16 countries, compared to the previous version, which targeted only 16 banking applications. Security researcher Vishnu Pratapagiri notes that this demonstrates a significant expansion in targeting scope and capabilities.
The new version of ToxicPanda also introduces an automated click-based mechanism to abuse Android Wireless Debugging via Android Debug Bridge (ADB) to facilitate privilege escalation and shell-level access on compromised devices. It achieves this by using the accessibility services to enable Developer Options and turn on Wireless debugging. Additionally, ToxicPanda 2.0 connects to its command-and-control (C2) server by sending an initial HTTPS request to establish a bidirectional WebSocket communication channel to receive commands and exchange data.
## GoldDigger Campaign The GoldDigger campaign, attributed to the Chinese-speaking threat actor GoldFactory, has also come under the security radar. This Android banking trojan was first documented by Group-IB in October 2023 and is capable of carrying out on-device fraud. GoldDigger makes use of a sophisticated packer called dpt-shell to obfuscate its code and resources, making it resistant to analysis.
The current GoldDigger campaign mainly impersonates airline companies and shopping retailers, resulting in a massive infection in South Africa and the U.K. Victims who install these apps are asked to grant accessibility services permissions, which the malware abuses for fraudulent actions. GoldDigger can inject input to the banking app to mimic user interaction, such as entering text, clicking buttons, and performing gestures.
## Comparison of ToxicPanda 2.0 and GoldDigger The following table compares the capabilities of ToxicPanda 2.0 and GoldDigger:
To stay safe against these threats, users are advised to review installed applications, audit app permissions, download apps only from trusted sources, keep devices up-to-date, enable two-factor authentication, and monitor bank accounts for unusual transactions. By taking these precautions, users can reduce the risk of falling victim to these Android banking trojans.





