Android users face a sharp rise in sophisticated banking malware. Two families in particular—ToxicPanda 2.0 (also tracked as TgToxic) and GoldDigger—illustrate how attackers have moved beyond simple credential theft to full on-device fraud. In these attacks, criminals remotely control the victim’s legitimate banking session and initiate transfers themselves.
Recent research from Zimperium zLabs and IBM Trusteer (building on earlier work by Group-IB) shows both campaigns have expanded in scale, technical capability, and geographic reach.
ToxicPanda 2.0: From Regional Threat to Global Platform
ToxicPanda has been active since at least July 2022. Earlier versions mainly focused on a small set of European banks (around 16 applications). The new 2.0 variant is a major upgrade:
- 167 remote commands (many previously unfinished features are now fully operational).
- Overlay-based credential theft targeting 349 banking, financial, e-wallet, and cryptocurrency applications across 16 countries, including Pakistan, South Africa, Mexico, Nigeria, India, Indonesia, Panama, and parts of southern Europe.
- A dedicated PIN-harvesting workflow aimed at more than 140 banking and crypto apps.
- Abuse of Android Accessibility Services to read every UI element, capture touches, and display convincing fake overlays on top of real banking apps.
- Automated abuse of Android Wireless Debugging (ADB) via accessibility-driven clicks. This allows the malware to enable developer options, capture pairing codes, and gain shell-level access without the user intentionally turning on debugging.
- Ability to steal lock-screen credentials with overlays, request Device Administrator privileges, overwrite the device PIN/password, and exempt itself from battery optimisation so it stays running.
- Use of VPN permissions to block Google Play and Play Protect communications, helping it stay undetected while it decrypts and installs its payload.
- Distribution via Amazon AWS-hosted buckets—showing the operators are comfortable using mainstream cloud infrastructure.
Once Accessibility Service access is granted, the malware can operate almost invisibly. Full-screen “system update” overlays hide activity, while transparent overlays capture PIN entry. Attackers can then perform transactions from the victim’s already-authenticated banking session—classic on-device fraud.
GoldDigger: On-Device Fraud as a Core Capability
GoldDigger, first documented by Group-IB in 2023 and linked to the Chinese-speaking GoldFactory group (also behind GoldPickaxe, GoldDiggerPlus, and GoldKefu), is built for the same style of attack.
Recent campaigns primarily impersonate airline and retail apps and have driven significant infections in South Africa and the United Kingdom, with code and target lists indicating wider global ambitions.
Key capabilities include:
- Heavy abuse of Accessibility Services to inject text, clicks, and gestures directly into banking apps—allowing attackers to initiate transfers themselves.
- Real-time screen viewing and input capture.
- Fake overlay dialogs that mimic bank login screens to harvest credentials.
- Ability to run targeted banking apps inside a virtual environment, giving the attacker full visibility into the app’s behaviour and the ability to intercept or modify sensitive data and identifiers.
- Collection of contacts, SMS, location, audio, and video (streamed via RTMP in some cases).
- Sophisticated packing and anti-analysis techniques that make reverse-engineering harder.
Like ToxicPanda, GoldDigger turns a compromised phone into a remote-controlled fraud terminal. Stolen credentials become less important than the ability to act as the legitimate user.
Why On-Device Fraud Is Especially Dangerous
Traditional banking malware often focused on stealing usernames, passwords, and one-time codes. On-device fraud goes further:
- The attacker operates inside an already logged-in, authenticated session.
- Many behavioural or device-based fraud controls struggle because the activity originates from the real user’s device and app.
- Accessibility Service abuse is powerful and hard for users to notice once granted.
- Privilege-escalation techniques (ADB abuse, Device Admin, lock-screen takeover) give attackers long-term control.
These campaigns show that mobile banking risk is no longer limited to “don’t click suspicious links.” The device itself has become the attack surface.
Practical Protection Steps for Individuals and Families
- Install apps only from the official Google Play Store. Avoid sideloading APKs, especially from “airline offers,” “shopping deals,” or “government portals.”
- Be extremely cautious with Accessibility Service requests. Legitimate apps rarely need this permission. If an unfamiliar app asks for it, refuse and uninstall.
- Keep Android and all banking apps fully updated. Many protections and Play Protect improvements arrive through system updates.
- Enable Google Play Protect and review its settings regularly.
- Use strong, unique device lock methods (biometric + strong PIN/pattern) and avoid reusing banking PINs as the device lock.
- Monitor banking notifications and transaction alerts in real time. Enable SMS/email/push alerts for every transfer.
- Review installed apps periodically and remove anything you do not recognise or no longer use.
- Never grant Device Administrator or VPN permissions to apps you do not fully trust.
- For higher-risk users, consider a dedicated secondary device or strong mobile threat-defence solutions that can detect accessibility abuse and suspicious overlays.
What Organisations and Banks Should Consider
- Monitor for Accessibility Service abuse and unusual ADB/wireless-debugging activity on corporate or BYOD fleets.
- Strengthen on-device and behavioural fraud detection that looks beyond simple credential reuse.
- Educate customers specifically about Accessibility Service prompts and the risks of sideloaded apps.
- Maintain close collaboration with mobile-security researchers and threat-intelligence providers tracking families such as ToxicPanda and GoldFactory.
Closing Thoughts
ToxicPanda 2.0 and GoldDigger demonstrate that Android banking malware has matured into flexible, remotely operated fraud platforms. By combining Accessibility Service abuse, overlays, privilege escalation, and cloud delivery, these campaigns can reach hundreds of financial apps across many countries and turn ordinary phones into tools for direct theft.
The good news is that the main entry points remain social engineering and excessive permissions. Careful app installation habits, scepticism toward Accessibility requests, and real-time transaction monitoring still stop the majority of these attacks.
Stay alert, keep software updated, and treat any unexpected permission request as a potential red flag. Awareness remains one of the strongest defences against on-device banking fraud.
Sources / Further reading
- Zimperium zLabs research on ToxicPanda 2.0 (August 2026)
- The Hacker News, SecurityWeek, BleepingComputer, and Infosecurity Magazine coverage
- IBM Trusteer analysis of GoldDigger
- Earlier Group-IB reporting on GoldDigger / GoldFactory
This article is for security-awareness purposes. Always verify the latest threat details with official banking and cybersecurity sources.