ToxicPanda 2.0 and GoldDigger: Android Banking Malware Evolves with Expanded Reach and Sophistication
New research highlights significant advancements in Android banking malware, with updated versions of **ToxicPanda** (aka **TgToxic**) and **GoldDigger** demonstrating expanded targeting capabilities and sophisticated evasion techniques. These threats leverage accessibility services, advanced packers, and cloud infrastructure to compromise financial data and gain unauthorized device access, posing a growing risk to mobile users globally.
Cybersecurity researchers are sounding the alarm on two highly evolved Android banking Trojans: **ToxicPanda 2.0** and **GoldDigger**. Both malware families have undergone significant enhancements, showcasing a dangerous trend in mobile threat landscapes with increased global reach and technical sophistication.
## ToxicPanda 2.0: A Global Threat with Enhanced Capabilities
**Zimperium zLabs** recently detailed an updated version of **ToxicPanda** that features a staggering 167 remote commands and significantly expands its global targeting. Active since at least July 2022, this new iteration, dubbed **ToxicPanda 2.0**, boasts a sophisticated PIN harvesting workflow targeting over 140 banking and cryptocurrency applications.
According to security researcher Vishnu Pratapagiri, the malware abuses Android's accessibility service to steal UI elements and employs an overlay-based credential theft mechanism. This latest version targets 349 financial institutions across 16 countries, a substantial increase from its predecessor, which only targeted 16 banking applications.

**ToxicPanda 2.0** also implements previously unimplemented commands, siphons lock screen credentials via fake overlays, and introduces an automated click-based mechanism to exploit **Android Wireless Debugging** through **Android Debug Bridge (ADB)**. This allows for privilege escalation and shell-level access on compromised devices by enabling Developer Options and Wireless debugging via accessibility services.
The malware establishes a bidirectional WebSocket communication channel with its command-and-control (**C2**) server to receive commands and exchange data. Similar to the recently discovered **Manic** malware, **ToxicPanda 2.0** can display full-screen "system update" overlays to conceal its background activities and deploy invisible transparent overlays to capture touch inputs and harvest PIN codes.
Additional functionalities include prompting victims for Device Administrator privileges, overwriting device lock screen PINs with attacker-defined values, and profiling devices to evade battery optimization policies, ensuring uninterrupted background execution.
**Zimperium** also noted a shift in distribution methods, with **ToxicPanda 2.0** samples now being delivered via **Amazon AWS**-hosted buckets, indicating a move towards leveraging cloud infrastructure for malware delivery.
## New GoldDigger Campaign Targets South Africa, U.K.
The third Android banking Trojan under the security spotlight is **GoldDigger**, first documented by **Group-IB** in October 2023 for its on-device fraud capabilities. It's attributed to **GoldFactory**, a Chinese-speaking threat actor linked to other banking malware families such as **GoldPickaxe**, **GoldDiggerPlus**, and **GoldKefu**, targeting both Android and iOS platforms.
**IBM Trusteer** reports that **GoldDigger** employs a sophisticated packer called "dpt-shell" to obfuscate its code and resources, making analysis challenging. This packer includes several evasion techniques, such as encrypting native logic, detecting and crashing processes if **Frida** is attached, and preventing external debuggers by marking itself as being traced using the **PTRACE** system call.
The current **GoldDigger** campaign primarily impersonates airline companies and shopping retailers, leading to a "massive infection" in South Africa and the U.K. Victims who install these malicious apps are tricked into granting accessibility service permissions, which the malware then abuses for fraudulent actions.
Security researcher Shahar Tavor Lusky explained that **GoldDigger** can inject input into banking apps, mimicking user interaction to initiate fraudulent transactions from the victim's account to the attacker's. Furthermore, **GoldDigger** provides operators with real-time access to the victim's screen, captures credentials via fake overlays on banking apps, and can run targeted applications within a virtual environment, granting attackers full visibility and real-time interception of sensitive data.
For **C2** communications, **GoldDigger** establishes a WebSocket connection, enabling it to request accessibility and location permissions, capture input from any app, collect contacts and SMS messages, record and stream audio/video via **RTMP**, open specific URLs, and launch specific apps like **Google Play Store** and **Settings**.
## Staying Secure
To mitigate the risks posed by these evolving threats, IT security professionals and privacy-conscious users are advised to:
* Regularly review installed applications and remove any unfamiliar or suspicious ones.
* Audit app permissions carefully before granting them.
* Download applications exclusively from trusted sources and developers.
* Keep devices and operating systems up-to-date with the latest security patches.
* Enable two-factor authentication (**2FA**) for all online accounts.
* Continuously monitor bank accounts and financial statements for any unusual or unauthorized transactions.
These proactive measures are crucial in safeguarding against the increasingly sophisticated tactics employed by mobile banking malware operators.