type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, android, banking-trojan, mobile-malware, credential-phishing] ยท confidence: medium ยท affected_sectors: [finance, technology] ยท au_impact: false
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks
Zimperium documented the updated Android banking trojan ToxicPanda (TgToxic) with 167 remote commands, PIN harvesting against more than 140 banking and cryptocurrency apps, and screen-capture-plus-overlay credential phishing across 349 financial institutions in 16 countries. The research extends the GoldDigger Android banking lineage into on-device fraud.
Key Facts
| Field | Detail |
|---|---|
| Malware | ToxicPanda (TgToxic) |
| Command-and-control capacity | 167 remote commands |
| Target scope | 140+ banking/crypto apps; 349 financial institutions in 16 countries |
| Techniques | Accessibility-service abuse, fake-overlay lock-screen capture, screen capture |
| Device compromise | Automated click chain enables the device using Android's Debug Bridge, then unlocks and shell-accesses the device |
| Status | Vendor research (Zimperium) |
Impact
The Android banking malware shifts the fraud surface onto the victim's device: overlays, PIN harvesting, and accessibility abuse turn the device itself into the harvest point. Financial-institution customers and mobile device fleets are both in the blast radius, and the on-device fraud pattern is harder for banks to distinguish from legitimate use.