Cybersecurity researchers have uncovered significant updates to the Android banking trojans ToxicPanda (aka TgToxic) and GoldDigger, both of which now feature enhanced on-device fraud capabilities and expanded global targeting.
Zimperium zLabs reported that ToxicPanda 2.0 includes 167 remote commands and a PIN harvesting workflow targeting over 140 banking and cryptocurrency apps. The malware abuses Android’s accessibility service to steal UI elements and uses overlay-based credential theft against 349 financial institutions across 16 countries, a major expansion from the previous version’s 16 banking apps. New features include automated click-based abuse of Android Wireless Debugging via ADB for privilege escalation, full-screen ‘system update’ overlays to hide malicious activity, and the ability to overwrite the device’s lock screen PIN. Distribution has shifted to Amazon AWS-hosted buckets, indicating use of cloud infrastructure for malware delivery.
GoldDigger, first documented by Group-IB in October 2023 and attributed to the Chinese-speaking threat actor GoldFactory, is now being used in campaigns impersonating airlines and retailers, causing massive infections in South Africa and the U.K. IBM Trusteer noted that GoldDigger uses the ‘dpt-shell’ packer to obfuscate code and evade analysis, including detecting Frida and preventing debuggers. The malware can inject input into banking apps to initiate fraudulent transactions, provide real-time screen access, capture credentials via fake overlays, and run targeted apps in a virtual environment. It uses WebSocket for C2, allowing commands to request permissions, capture input, collect contacts and SMS, record audio/video, and open specific URLs or apps.
To mitigate these threats, users should review installed apps, audit permissions, download only from trusted sources, keep devices updated, enable two-factor authentication, and monitor bank accounts for unusual activity.
Attack groups: GoldFactory
Malware: ToxicPanda, GoldDigger, GoldPickaxe, GoldDiggerPlus, GoldKefu, Manic
Companies: Zimperium, Group-IB, IBM
Products: Zimperium zLabs, IBM Trusteer
Original source: thehackernews.com