Researchers at Zimperium zLabs have detailed ToxicPanda 2.0, an upgraded Android banking trojan that expands on-device fraud capabilities and now carries 167 remote commands.
Also known as TgToxic and active since at least July 2022, the malware abuses the Android accessibility service to steal every UI element on screen. Its overlay-based credential theft now targets 349 financial institutions across 16 countries, up from 16 banking apps in the previous version, and it harvests PINs from more than 140 banking and cryptocurrency applications.
New capabilities include a fake overlay that siphons lock screen credentials, full-screen “system update” overlays that hide background activity, and an automated click mechanism that enables Developer Options and Wireless Debugging to reach ADB shell access. It also prompts victims to grant Device Administrator privileges and can overwrite local lock settings. Samples are now delivered through Amazon AWS-hosted buckets, a shift in distribution.
Command and control runs over an HTTPS-initiated WebSocket channel that can request permissions, capture input, collect contacts and SMS, and stream audio and video.
In the same report, IBM Trusteer flagged a fresh GoldDigger campaign impersonating airlines and shopping retailers, causing “massive infection” in South Africa and the UK. GoldDigger, linked to the Chinese-speaking GoldFactory group, injects input into banking apps to mimic user interaction and push fraudulent transactions, while the dpt-shell packer resists analysis and detects debuggers.
Users should audit installed apps, review permissions, and enable two-factor authentication on bank accounts.
