Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ToxicPanda 2.0 and GoldDigger Amplify Android Threats

ToxicPanda 2.0 and GoldDigger Amplify Android Threats

Posted on August 20, 2026 By CWS

Cybersecurity experts have uncovered a new iteration of the ToxicPanda malware, significantly enhancing its capabilities and expanding its global reach. Known for its ability to conduct on-device fraud, ToxicPanda 2.0 now boasts 167 remote commands, targeting over 140 banking and cryptocurrency applications worldwide.

Enhanced Capabilities of ToxicPanda 2.0

The Android malware exploits the operating system’s accessibility services, enabling cybercriminals to capture every UI element on the screen. This iteration vastly increases its attack surface, now targeting 349 financial institutions across 16 countries, compared to the previous focus on just 16 applications. Its new features include a PIN harvesting workflow and the ability to siphon lock screen credentials using fake overlays.

In addition, the malware automates privilege escalation by abusing Android Wireless Debugging via the Android Debug Bridge (ADB). This is achieved through accessibility services that activate Developer Options and enable Wireless Debugging, providing attackers shell-level access.

Communication and Delivery Tactics

ToxicPanda 2.0 connects to a command-and-control (C2) server through an initial HTTPS request, establishing a WebSocket communication channel for data exchange. The malware can also display full-screen system update overlays to hide its activities while capturing touch inputs and PIN codes using transparent overlays.

Furthermore, there is a notable shift in how the malware is distributed. Attackers now use Amazon AWS-hosted buckets for delivery, demonstrating a strategic move to leverage cloud infrastructure for deploying malware.

GoldDigger’s Campaign in South Africa and the UK

The GoldDigger malware, linked to the GoldFactory threat group, has been identified as another major player in Android banking threats. First reported by Group-IB in October 2023, it uses a sophisticated packer to obfuscate its code, making analysis difficult. This malware primarily targets South Africa and the UK by masquerading as airline and retail apps.

GoldDigger employs accessibility services to mimic user interactions within banking apps, initiating unauthorized transactions. It can also provide real-time access to the victim’s screen and capture credentials via fake overlays, giving attackers extensive visibility and control over the infected device.

Users are advised to remain vigilant by reviewing app permissions and ensuring their devices are up-to-date. Downloading apps from trusted sources and enabling two-factor authentication (2FA) for online accounts are also recommended to mitigate these threats.

The Hacker News Tags:Android security, banking malware, cyber attacks, cyber defense, Cybersecurity, GoldDigger, IBM Trusteer, Malware, mobile security, mobile threats, on-device fraud, Threat Actors, ToxicPanda 2.0, Zimperium

Post navigation

Previous Post: Malicious Firefox Extensions Target Crypto Wallets
Next Post: MLflow Flaw Exploited for Credential Theft in Cloud

Related Posts

Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions The Hacker News
Hugging Face Diffusers Security Flaws Threaten AI Systems Hugging Face Diffusers Security Flaws Threaten AI Systems The Hacker News
New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data The Hacker News
China-Made Routers Exposed to Critical Security Breaches China-Made Routers Exposed to Critical Security Breaches The Hacker News
Critical Linux Vulnerability Exposes Systems to Root Attacks Critical Linux Vulnerability Exposes Systems to Root Attacks The Hacker News
QuickFox VPN Targeted in Supply Chain Attack Exposing Users QuickFox VPN Targeted in Supply Chain Attack Exposing Users The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark