An upgraded strain of the ToxicPanda malware—dubbed ToxicPanda 2.0—is now capable of far more powerful Android banking attacks and fraud operations. Security analysts from Zimperium zLabs have revealed a major expansion in the malware’s functionality and global reach. Meanwhile, a refreshed campaign by the GoldDigger trojan is running widespread attacks across South Africa and the UK.
ToxicPanda 2.0: Broadened Targeting & New Capabilities
ToxicPanda has been active since at least July 2022. The new 2.0 version supports 167 remote commands—a massive jump from earlier iterations. Now it can harvest PINs from over 140 banking and crypto apps. Previously, ToxicPanda targeted just 16 banking applications. This version abuses Android’s accessibility service to capture every UI element on the screen and uses overlay-based overlays to trick users into handing over credentials. Fake lock screen overlays are also part of its attack toolkit.([thehackernews.com](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html))
Further, the malware can exploit Android debugging to escalate privileges. It uses Android Debug Bridge (ADB) to turn on wireless debugging and enable Developer Options, gaining shell-level access. Communication with its command-and-control server is handled via secure HTTPS and WebSocket, enabling real-time bidding on commands and data. To mask its operations, ToxicPanda displays system update prompts and transparent overlays to steal PINs from users.([thehackernews.com](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html))
The new version can also force Device Administrator status on infected devices, replace existing lock screen PINs or passwords with attacker-controlled ones, and profile devices to determine manufacturer so it can evade battery optimization limitations. The attackers are distributing the malware using Amazon AWS buckets, showing a shift toward using cloud infrastructure to deliver malicious payloads.([thehackernews.com](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html))
GoldDigger: On-Device Fraud Escalates in South Africa & the UK
Also under scrutiny is a current campaign from GoldDigger, a banking trojan first documented in October 2023. It is linked to the threat actor known as GoldFactory, associated with hybrid malware families like GoldPickaxe, GoldDiggerPlus, and GoldKefu. The current wave of infections is concentrated in South Africa and the UK, with the malware masquerading as airline or shopping apps.([thehackernews.com](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html))
GoldDigger uses a custom packer called “dpt-shell” to obscure its code and evade detection. Among its evasion tricks are encrypted logic, crashing if debugging tools like Frida are detected, and blocking external debuggers via PTRACE checks.([thehackernews.com](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html))
Once installed, it asks the user for accessibility service permissions. With those, it can imitate user activity—typing, clicking, performing gestures—to conduct fraudulent transactions. GoldDigger also overlays fake screens to trick users into revealing credentials, gains real-time access to display output, and can run banking apps inside virtual environments to monitor app behavior closely. Its control over C2 servers is robust, enabling it to collect credentials, location, contacts, SMS, audio/video streams (via RTMP), and more.([thehackernews.com](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html))
Protection Tips: What Users Must Do
To defend against these threats, users should scrutinize installed apps and uninstall anything suspicious. Review permissions before granting them, especially for accessibility and administrator privileges. Stick to trusted app stores and developers. Keep devices updated. Enable two-factor authentication for online accounts. Watch financial statements and transactions carefully for anything out of order.([thehackernews.com](https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html))
This latest escalation with ToxicPanda 2.0 and GoldDigger signals a worrying shift in Android banking malware. The scale, stealth, and sophistication have all increased dramatically. Going forward, defenses will need not just careful user behavior, but stronger controls in the Android ecosystem itself—tighter restrictions on overlays, more comprehensive vetting of apps requesting elevated permissions, and better tools for real-time detection of on-device fraud. We’ll be monitoring how Android platform owners respond to this growing threat landscape.