Interestana
Home/News/ToxicPanda 2.0 and GoldDigger Android Malware Escalate On-Device Fraud
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

ToxicPanda 2.0 and GoldDigger Android Malware Escalate On-Device Fraud

ToxicPanda 2.0 and GoldDigger Android Malware Escalate On-Device Fraud

Cybersecurity researchers have detailed significant enhancements to the Android banking malware known as ToxicPanda, now referred to as ToxicPanda 2.0 or TgToxic. In a report published on Wednesday, Zimperium zLabs revealed that this updated version boasts a robust set of 167 remote commands, expanding its operational capabilities and global reach. The malware is designed to target a wide array of financial applications, with a specific focus on a PIN harvesting workflow that targets over 140 banking and cryptocurrency applications. This sophisticated approach allows ToxicPanda 2.0 to gather sensitive user credentials directly on the compromised device, bypassing traditional server-side detection methods.

Alongside the advancements in ToxicPanda 2.0, the report also highlights the continued threat posed by the GoldDigger malware. GoldDigger, which has been active since at least September 2023, is known for its ability to perform overlay attacks and SMS phishing to steal banking credentials. Researchers observed GoldDigger utilizing a technique where it overlays legitimate banking applications with fake login screens, tricking users into entering their usernames and passwords. This method, combined with its SMS phishing capabilities to intercept one-time passwords (OTPs) or verification codes, allows GoldDigger to effectively compromise user accounts and facilitate fraudulent transactions. The malware's primary targets include applications from major financial institutions in Australia, with a focus on stealing credentials for online banking services.

Both ToxicPanda 2.0 and GoldDigger represent a growing trend in mobile malware that focuses on on-device fraud, exploiting the trust users place in their mobile banking applications. The ability of these malware families to execute complex command sets and employ sophisticated social engineering tactics like overlay attacks underscores the evolving threat landscape for Android users. The global targeting footprint of ToxicPanda 2.0, coupled with GoldDigger's specific focus on Australian financial institutions, indicates a broad and persistent effort by threat actors to exploit vulnerabilities in the mobile financial ecosystem. The researchers at Zimperium zLabs emphasize the critical need for enhanced security measures and user vigilance to combat these evolving threats that aim to steal financial information directly from user devices.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next