What Is ToxicPanda 2.0?
ToxicPanda 2.0 is an updated version of an Android banking trojan that has circulated since mid-2022. Researchers recently uncovered major upgrades to the malware. It now carries 167 remote commands, far more than earlier versions. Therefore, attackers can control infected phones in far more detailed ways.
The malware also includes a PIN-harvesting feature. It targets more than 140 banking and cryptocurrency apps. As a result, victims across many countries face real financial risk.
Expanded Targeting and Capabilities
According to the report, ToxicPanda 2.0 now targets 349 financial institutions across 16 countries. This is a huge jump from the previous version, which only targeted 16 banking apps. Consequently, the malware’s reach has grown dramatically.
The malware abuses Android’s accessibility service to read everything shown on screen. For example, it can overlay a fake login screen to steal credentials. It also enables wireless debugging without the user’s knowledge. This gives attackers deeper access to the device.
How the Malware Operates
ToxicPanda 2.0 connects to its control server using a secure web connection. Once connected, it can display fake “system update” screens. Meanwhile, it silently records taps to capture PIN codes underneath.
Additionally, the malware can trick users into granting administrator access. It can then change the device’s lock screen password. Furthermore, it adjusts battery settings so it keeps running in the background undetected. Notably, recent samples were distributed through legitimate cloud storage services, making detection harder.
A second Android banking trojan, known as GoldDigger, is also expanding its reach. First identified in 2023, it specializes in on-device fraud. Currently, it is spreading rapidly across South Africa and the United Kingdom.
The malware uses a sophisticated packing tool to hide its code from analysts. For instance, it detects debugging tools and shuts itself down if one is found. This makes GoldDigger difficult for security teams to study.
How GoldDigger Tricks Victims
GoldDigger often disguises itself as airline or shopping apps. Once installed, it asks for accessibility permissions. Victims who grant this access unknowingly hand over control of their banking apps.
The malware can then simulate taps, typing, and gestures inside banking apps. In doing so, it initiates fraudulent transactions automatically. It can also stream a victim’s screen in real time and record audio or video without permission.
Shared Techniques, Growing Risk
Both malware families rely on Android’s accessibility service as their main weapon. Similarly, both use fake overlays to steal credentials and PINs. However, each family targets slightly different regions and industries.
Together, these campaigns show a clear trend. Mobile banking malware is becoming more advanced and harder to detect.
How to Stay Protected
Start by reviewing installed apps regularly and removing anything unfamiliar. Always check permissions before granting them, and only download apps from trusted sources. In addition, keep your device updated and enable two-factor authentication wherever possible.
For businesses, a managed detection and response service can flag suspicious accessibility-service activity before fraud occurs. Meanwhile, ongoing threat intelligence monitoring helps security teams catch new malware variants early, often before they spread widely. Combining good personal habits with layered security defenses gives users and organizations the strongest protection against threats like ToxicPanda 2.0 and GoldDigger.

