negativeSYS.SOURCE: The Hacker News• 2026-08-20T16:08:28+05:30
Advanced Android Banking Malware ToxicPanda 2.0 and GoldDigger Employ On-Device Fraud Techniques
ToxicPanda 2.0 expands Android banking attacks with 167 remote commands and targets 140+ financial apps via accessibility services, while GoldDigger uses advanced obfuscation and on-device fraud techniques to steal credentials from South Africa and the UK.
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally.
Zimperium zLabs, in a Wednesday report, said the Android malware also features a PIN harvesting workflow targeting more than 140 banking and cryptocurrency applications.
*** END OF TRANSMISSION ***