A malware family capable of hijacking Android phones and quietly emptying banking apps has just become significantly more dangerous, according to new research that traces its evolution from a modest regional threat into a tool now capable of targeting hundreds of financial institutions worldwide. Security researchers at Zimperium zLabs have documented major upgrades to ToxicPanda 2.0, also tracked as TgToxic, alongside a parallel campaign called GoldDigger that has already caused widespread infections abroad.
The findings arrive as Indian users increasingly rely on smartphones for banking, UPI transfers and investment activity, a shift that has made Android accessibility abuse one of the most consequential and least visible cybersecurity threats facing ordinary account holders today.
A Malware Family That Has Outgrown Its Origins
ToxicPanda has reportedly been active since at least July 2022, but the version now circulating represents a substantial leap in capability. Researchers found it supports 167 remote commands and has expanded its targeting from just 16 banking applications in earlier iterations to more than 140 banking and cryptocurrency apps, with credential-theft infrastructure capable of reaching 349 financial institutions across 16 countries.
The malware’s core technique relies on abusing Android’s accessibility services, a feature originally designed to assist users with disabilities, to read on-screen content and interact with applications on the victim’s behalf. It layers fake overlay screens atop legitimate banking interfaces, tricking users into entering PINs and credentials directly into what appears to be their genuine banking app. Similar overlay-based deception has been documented in comparable malware families circulating globally through 2026, underscoring how this technique has become a standard component of the modern Android banking trojan.
More alarmingly, ToxicPanda 2.0 can reportedly manipulate Android’s Wireless Debugging and Developer Options settings through automated clicks, gaining elevated shell-level access that dramatically increases attacker control over an infected device. It communicates with command servers through an encrypted WebSocket channel, and can display convincing fake system-update screens to mask malicious activity running in the background.
Distribution Through Trusted Infrastructure
Perhaps most concerning for detection efforts, researchers observed that samples of the updated malware were distributed through Amazon AWS-hosted storage, indicating attackers are increasingly hiding malicious payloads within legitimate cloud infrastructure rather than obviously suspicious hosting services. This blending into trusted digital environments makes conventional filtering and blacklisting approaches considerably less effective.
The malware has also gained the ability to persuade victims into granting Device Administrator privileges, after which it can reportedly replace an infected phone’s existing lock-screen PIN with one chosen by the attacker, effectively locking the genuine owner out while the fraudster retains full control. It further profiles each device by manufacturer to bypass battery-optimisation restrictions specific to that model, allowing it to persist in the background for extended periods without triggering system alerts.
GoldDigger’s Parallel Campaign and the Broader Threat Landscape
Alongside ToxicPanda’s evolution, researchers are tracking GoldDigger, an Android banking trojan first documented by Group-IB in 2023 and linked to the Chinese-speaking threat actor GoldFactory, whose malware family also includes GoldPickaxe and GoldKefu. According to IBM Trusteer, GoldDigger uses a sophisticated packer to conceal its code, encrypt native components and actively detect security research tools, making it considerably harder for defenders to analyse.
The latest GoldDigger campaign impersonates airline and retail applications, causing widespread infections across South Africa and the United Kingdom. Once installed, it can simulate user actions directly inside banking apps, including typing, clicking and gesture inputs, allowing attackers to initiate fraudulent transactions using the victim’s own authenticated banking session rather than stolen credentials alone.
India has faced comparable threats from its own crop of Android banking trojans in recent years, with security researchers previously documenting malware disguised as utility and banking apps specifically targeting Indian users, in some cases intercepting thousands of SMS messages and harvesting card details before detection. Security experts recommend downloading applications exclusively from trusted developers, reviewing app permissions carefully, keeping devices updated, enabling two-factor authentication and monitoring bank accounts regularly, since accessibility-based malware of this kind is specifically engineered to operate invisibly until funds have already moved.