Trojan Viruses Expand Android Banking Attacks
Cybersecurity researchers have identified significant updates to two Android banking trojans, ToxicPanda and GoldDigger, highlighting the growing sophistication of mobile malware targeting financial information. ToxicPanda, also known as TgToxic, has received a major upgrade that expands its capabilities and dramatically increases the number of financial institutions it can target. Researchers from Zimperium’s zLabs team say the new version, ToxicPanda 2.0, contains 167 remote commands and is capable of targeting hundreds of financial institutions across multiple countries.
ToxicPanda has been active since at least 2022, but the latest version represents a substantial expansion of its capabilities. One of its most concerning features is its ability to abuse Android’s accessibility services. These services are designed to help users interact with their devices, but malware can misuse them to read information displayed on the screen and perform actions on the victim’s behalf. ToxicPanda 2.0 uses this functionality to collect information from applications and assist with credential theft.
The malware has also expanded its targeting considerably. Earlier versions reportedly focused on a much smaller number of banking applications, while ToxicPanda 2.0 now includes an overlay-based credential theft mechanism targeting 349 financial institutions across 16 countries. Researchers also identified functionality designed to harvest PINs from more than 140 banking and cryptocurrency applications. By placing deceptive screens or invisible overlays over legitimate applications, the malware can capture sensitive information without making the victim immediately aware that anything unusual is happening.
Another important development is ToxicPanda 2.0’s ability to obtain lock-screen credentials. The malware can display fraudulent overlays designed to trick users into entering their device PIN or password. It can also replace the existing lock-screen PIN or password with a value chosen by the attacker, potentially giving the operator greater control over the compromised device.
Researchers also discovered that ToxicPanda 2.0 can manipulate Android’s Wireless Debugging functionality. Through accessibility services, the malware can automatically enable Developer Options and Wireless Debugging and then use Android Debug Bridge, or ADB, to obtain additional privileges and shell-level access. This provides attackers with another avenue for controlling the infected device and carrying out actions that would otherwise require greater permissions.
The malware communicates with its command-and-control infrastructure using HTTPS to establish an initial connection before switching to a bidirectional WebSocket channel. This allows attackers to send commands to compromised devices and receive information in return. ToxicPanda can also display convincing full-screen system-update screens to hide malicious activity taking place in the background. In some cases, it can place an invisible overlay over the device interface to capture touch interactions and PIN entries while the victim continues using the phone.
ToxicPanda 2.0 includes several additional mechanisms designed to maintain control of infected devices. For example, it can attempt to persuade victims to grant Device Administrator privileges, which can make removing the malware more difficult. It can also inspect the infected device to determine its manufacturer and adjust its behavior accordingly. The malware may then attempt to bypass Android’s battery-optimization restrictions so that it can continue running in the background without being terminated.
Researchers also observed a change in how ToxicPanda is distributed. Samples of the updated malware have been hosted in Amazon Web Services cloud storage buckets, suggesting that the attackers are increasingly using legitimate cloud infrastructure to distribute malicious applications. Using cloud services can make malicious infrastructure more flexible and potentially more difficult to identify and take down.
At the same time, security researchers are tracking new activity involving another Android banking trojan known as GoldDigger. First documented in 2023, GoldDigger has been associated with on-device fraud and is attributed to GoldFactory, a Chinese-speaking threat actor linked to several other Android and iOS banking malware families.
The latest GoldDigger campaign has primarily targeted victims in South Africa and the United Kingdom. Attackers have reportedly disguised malicious applications as legitimate airline companies and retail businesses in an effort to persuade users to install them. Once installed, the malware attempts to convince victims to grant accessibility permissions. With those permissions, GoldDigger can interact directly with other applications and effectively automate actions that would normally be performed by the user.
This capability allows GoldDigger to interact with banking applications, including entering text, pressing buttons, and performing gestures. Attackers can therefore use the victim’s own banking application to initiate fraudulent transactions. The malware can also provide criminals with real-time visibility into the victim’s screen and use deceptive overlays to capture credentials entered into financial applications.
GoldDigger contains additional surveillance capabilities that extend beyond banking credentials. Researchers found that the malware can collect information such as contacts and SMS messages, capture input from other applications, and request access to sensitive device permissions. It can also record audio and video and stream that information back to its command-and-control infrastructure. In addition, attackers can instruct the malware to open specific websites or applications, including Android’s Settings and Google Play Store.
The malware has also incorporated measures designed to make analysis more difficult. GoldDigger uses a sophisticated packer known as dpt-shell to obscure its code and resources. Its defenses include encrypting portions of its native functionality, detecting security research tools such as Frida, and using Android debugging protections to make it harder for researchers to inspect its behavior.
The emergence of these updated banking trojans demonstrates how Android malware is becoming increasingly capable of performing financial fraud directly on victims’ devices. Rather than simply stealing banking credentials and sending them to attackers, modern threats such as ToxicPanda 2.0 and GoldDigger can manipulate legitimate banking applications, capture information displayed on screens, and perform actions that appear to originate from the victim.







