logo

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

ID: bbfbb747-f9fd-55d1-b0c2-c76fbcd224b7

STIX ID: report--bbfbb747-f9fd-55d1-b0c2-c76fbcd224b7

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

Author: [email protected] (The Hacker News)

...
...

Security researchers disclosed updated Android banking trojans: ToxicPanda 2.0 expands to 167 remote commands, harvests PINs via overlays, abuses Android accessibility and Wireless Debugging (ADB) for privilege escalation, and uses AWS-hosted buckets for delivery; GoldDigger uses a sophisticated packer and accessibility abuse to conduct on-device fraud, stream audio/video, capture credentials, and has caused mass infections in South Africa and the U.K.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.