Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Malware Analysis
  5. ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

Scheduled Pinned Locked Moved Malware Analysis
android
1 Posts 1 Posters 5 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Researchers have detailed an updated iteration of ToxicPanda (also tracked as TgToxic), which now ships with a considerably expanded command set and a broader geographic reach. The new version includes 167 distinct remote commands, a notable upgrade over earlier builds, and introduces a dedicated PIN harvesting routine aimed at over 140 banking and cryptocurrency apps.

    According to a Wednesday report from Zimperium zLabs, the malware's enhancements are not limited to its command structure. The newer variant also refines its on-device fraud capabilities, allowing attackers to interact directly with compromised devices rather than relying solely on overlays or credential theft. This shift enables more dynamic manipulation of legitimate sessions, which complicates detection by both users and security tools.

    Key details from the analysis:

    • ToxicPanda 2.0 now supports 167 remote commands, up from previous versions.
    • The PIN harvesting workflow targets more than 140 financial and crypto-related applications.
    • The malware's targeting footprint has expanded to additional regions beyond its original scope.
    • The updates align with ongoing developments in the GoldDigger family, which similarly focuses on on-device fraud techniques.

    The expansion of both ToxicPanda and GoldDigger underscores a growing trend among Android banking trojans: moving from simple overlay attacks to more sophisticated, interactive fraud that occurs in real time on the victim's device. For defenders, this means monitoring for anomalous device behavior and unexpected accessibility service usage remains critical.

    Source: The Hacker News

    Has your organization's mobile threat detection flagged any anomalies linked to these updated command sets, or are you adjusting your Android security posture in response to the broader on-device fraud trend?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World