Cybersecurity researchers have highlighted a sophisticated update to the ToxicPanda Android banking Trojan, exposing an expanded operational capability designed to carry out on-device financial fraud. Active since at least July 2022, the updated malware iteration incorporates 167 remote commands and broadens its scope to target 349 financial institutions across 16 countries, alongside a specialized PIN-harvesting workflow directed at over 140 cryptocurrency and banking applications. According to technical analysis by Zimperium zLabs, the updated malware systematically abuses Android accessibility services to steal interface elements, capture lock screen credentials using fake system overlays, and trick users into granting Device Administrator privileges. Additionally, it automates interactions to activate Developer Options and turn on Wireless Debugging via Android Debug Bridge, granting threat actors elevated shell-level access on infected devices.
The deployment mechanics of ToxicPanda have also evolved to utilize Amazon AWS-hosted infrastructure for delivering payloads, signaling a transition toward leveraging public cloud platforms for malware distribution. Once installed, the Trojan initiates bi-directional WebSocket communication over an initial HTTPS request to receive instructions from its command server. To obscure its activities during exploitation, it displays full-screen fake system update overlays or invisible transparent touch-capturing interfaces that log user PINs. It also checks the original equipment manufacturer profiles of compromised hardware, automatically adjusting system settings to bypass standard battery optimization policies and guarantee continuous background execution.
Concurrently, security analysts have identified updated campaigns involving the GoldDigger banking Trojan, an Android threat family operated by the Chinese-speaking group GoldFactory. Initially documented by Group-IB, recent GoldDigger variants have caused widespread infections across South Africa and the United Kingdom by impersonating legitimate airline portals and retail applications. To resist reverse engineering and security analysis, the malware uses a protective packer that encrypts native logic, terminates runtime processes if analysis tools like Frida are detected, and uses system calls to block external debuggers. After tricking victims into granting accessibility permissions, GoldDigger performs on-device fraud by mimicking user interactions, entering stolen credentials, clicking buttons, and initiating unauthorized financial transfers directly within legitimate banking applications.
The GoldDigger threat family provides operators with real-time screen access, credential harvesting capabilities, and the ability to execute targeted financial applications inside virtual environments to monitor runtime behavior. Its WebSocket connection enables remote operators to collect contacts, intercept text messages, record ambient audio or video, and stream live media via RTMP protocols back to command servers. Security experts recommend that users continuously review installed applications, audit granted system permissions, avoid downloading software from unverified third-party sources, keep operating systems fully updated, and enforce multi-factor authentication across sensitive accounts.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.