ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On
Zimperium and IBM Trusteer report expanded ToxicPanda 2.0 and GoldDigger Android banking trojan campaigns now targeting 349 financial institutions across 16 countries.
Zimperium zLabs reports ToxicPanda 2.0 (TgToxic) now carries 167 remote commands, targets 349 financial institutions across 16 countries via more than 140 banking and cryptocurrency apps, and abuses Android Wireless Debugging via ADB for privilege escalation and shell access. It harvests lock screen PINs with fake overlays, steals UI elements via accessibility services, sets Device Administrator privileges, and is distributed through Amazon AWS-hosted buckets. IBM Trusteer documents a GoldDigger campaign impersonating airline companies and shopping retailers, causing massive infections in South Africa and the U.K., obfuscated with the dpt-shell packer that detects Frida and resists debugging. GoldDigger performs on-device fraud by injecting input into banking apps and is attributed to the Chinese-speaking GoldFactory actor.
ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
Zimperium documents ToxicPanda 2.0, an Android banking trojan now targeting 349 financial institutions in 16 countries via ADB privilege escalation and overlay credential theft.
Zimperium's zLabs documented ToxicPanda 2.0, an Android banking trojan expanding from 16 targeted apps to 349 financial institutions across 16 countries, with 167 remote commands. It poses as a dropper, abuses VPN permissions to block Google Play Protect while installing a hidden payload, then uses the Accessibility Service for screen monitoring and overlay-based credential theft. It automates enabling Android Wireless Debugging and completes the pairing handshake to gain ADB shell access for privilege escalation, and overlays fake lock screens to steal device PINs. Previously unfinished commands are now operational and samples are served from AWS-hosted storage buckets.
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
ThreatFabric identified Manic, an Android banking malware and spyware targeting Ukrainian and European financial apps with novel offline Wi-Fi mesh data exfiltration via nearby infected devices.
ThreatFabric reported a new Android malware family called Manic combining banking fraud and surveillance capabilities, targeting 169 package IDs across Ukrainian banks, government and identity services, messaging apps, and Russian and European financial institutions. The malware uses phishing sites and dropper apps impersonating utilities for distribution and relies on accessibility services and notification permissions for keylogging, overlays, and remote control. It introduces a store-and-forward relay mechanism that stages encrypted data locally and relays it through nearby infected devices via Wi-Fi Direct, Bluetooth RFCOMM, or BLE GATT, supporting up to four hops when the primary device lacks internet access. Activity dates back to February 2026, with active development through late July.