Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, android, banking-trojan, mobile-malware, credential-phishing] ยท confidence: medium ยท affected_sectors: [finance, technology] ยท au_impact: false

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks

Zimperium documented the updated Android banking trojan ToxicPanda (TgToxic) with 167 remote commands, PIN harvesting against more than 140 banking and cryptocurrency apps, and screen-capture-plus-overlay credential phishing across 349 financial institutions in 16 countries. The research extends the GoldDigger Android banking lineage into on-device fraud.

Key Facts

Field Detail
Malware ToxicPanda (TgToxic)
Command-and-control capacity 167 remote commands
Target scope 140+ banking/crypto apps; 349 financial institutions in 16 countries
Techniques Accessibility-service abuse, fake-overlay lock-screen capture, screen capture
Device compromise Automated click chain enables the device using Android's Debug Bridge, then unlocks and shell-accesses the device
Status Vendor research (Zimperium)

Impact

The Android banking malware shifts the fraud surface onto the victim's device: overlays, PIN harvesting, and accessibility abuse turn the device itself into the harvest point. Financial-institution customers and mobile device fleets are both in the blast radius, and the on-device fraud pattern is harder for banks to distinguish from legitimate use.

Source