167 remote commands, a PIN-harvesting workflow for more than 140 banking and crypto apps, and overlays that can steal lock‑screen credentials — those are among the headline capabilities researchers say have been added to a new ToxicPanda release.
ToxicPanda 2.0: expanded command set and persistent C2
Security researchers at Zimperium zLabs describe the updated ToxicPanda (aka TgToxic) as a substantially enhanced Android banking trojan. The new build contains a set of 167 remote commands and connects to its command‑and‑control (C2) by sending an initial HTTPS request to establish a bidirectional WebSocket channel to receive commands and exchange data, the report says. ToxicPanda has been active in the wild since at least July 2022, and this iteration both broadens its scope and fills in previously unimplemented functionality.
On‑device fraud: accessibility abuse, overlays, and PIN harvesting
Zimperium details multiple techniques ToxicPanda 2.0 uses to steal credentials and maintain persistence. By abusing Android accessibility services, the malware can "steal every UI element on the screen," and it deploys overlay‑based credential theft mechanisms that now target 349 financial institutions across 16 countries — up from an earlier version that targeted only 16 banking applications, researcher Vishnu Pratapagiri said. The malware can display full‑screen "system update" overlays to hide background activity and use invisible transparent overlays to capture touch input and harvest PIN codes. It can also siphon lock‑screen credentials through a fake overlay.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePrivilege escalation and device control: wireless debugging and device admin tricks
ToxicPanda 2.0 adds an automated, click‑based mechanism to abuse Android Wireless Debugging via the Android Debug Bridge (ADB). The malware uses accessibility services to enable Developer Options and turn on Wireless debugging, facilitating privilege escalation and shell‑level access on compromised devices. Additional new capabilities include prompting victims to grant Device Administrator privileges, overwriting the device's local lock‑screen PIN or password with an attacker‑defined value, and profiling the device to determine the OEM vendor so the malware can exempt itself from battery optimization policies — all intended to ensure uninterrupted background execution.
GoldDigger's new campaign: impersonation, on‑device fraud, and real‑time control
Separately, researchers flagged a new GoldDigger campaign that has produced a "massive infection" in South Africa and the U.K., according to IBM Trusteer. First documented by Group‑IB in October 2023 as an on‑device fraud threat, GoldDigger is attributed to GoldFactory, a Chinese‑speaking group linked to several related mobile banking families. The current campaign mainly impersonates airline companies and shopping retailers to trick victims into installing malicious apps and granting accessibility permissions.
IBM Trusteer reports GoldDigger is protected by a sophisticated packer called "dpt‑shell" that obfuscates code and implements multiple evasion techniques: encrypting native logic; detecting and crashing if Frida is attached; and preventing external debuggers by marking the process as being traced using the PTRACE system call. Once present, GoldDigger can inject input into banking apps to mimic user interaction — entering text, clicking buttons, and performing gestures — allowing operators to initiate fraudulent transactions from the victim's banking app, researcher Shahar Tavor Lusky said.
Capabilities common to both threats and their infrastructure choices
Both families use accessibility services as a central enabler of on‑device fraud: capturing inputs and UI elements, requesting permissions, and automating interactions. Both establish WebSocket connections for C2 commanding. GoldDigger's WebSocket support lets operators request accessibility and location permissions, capture input from any app, collect contacts and SMS messages, record audio and video and stream it via RTMP to the C2, and open specific URLs or apps (for example, Google Play Store and Settings).
Zimperium also notes a change in distribution tactics for ToxicPanda 2.0: samples are being delivered through Amazon AWS‑hosted buckets, indicating the adversary is leveraging cloud infrastructure for malware delivery. The report also parallels some behaviors to the newly‑discovered Manic malware family in how overlays are used to conceal actions.
What this means for security teams, financial institutions, and end users
- Security teams and technologists: Expect mobile threats to rely more on accessibility‑service abuse, overlay deception, WebSocket C2, and cloud storage for delivery. Monitor for unusual enabling of Developer Options or Wireless Debugging, Device Administrator requests, and processes that attempt to exempt themselves from battery optimization.
- Financial institutions and fraud teams: On‑device automation that injects input and performs gestures bypasses traditional remote‑authentication heuristics. Monitor for transactions that could originate from automated app interactions and review authentication flows that assume only human input.
- End users: Researchers advise reviewing installed applications and removing unfamiliar ones, auditing app permissions before granting them (especially accessibility and device admin), downloading apps only from trusted sources and developers, keeping devices up to date, enabling two‑factor authentication for online accounts, and monitoring bank accounts for unusual transactions.
ToxicPanda 2.0 and the current GoldDigger campaign underline a simple tactical shift: rather than relying solely on remote servers or generic credential theft, these families seek control and visibility inside the device itself. That interior access — overlays that capture PINs, injected gestures that trigger transfers, persistent exemptions from power management — turns a compromised handset into an active fraud platform. The practical question left by the reporting is whether detection and response workflows will rise to meet that shift inside the mobile runtime, and how rapidly defenders can identify and block the cloud delivery vectors now in use.




