GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
Campaign
Summary
Hide ▲
Show ▼
A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigger fraudulent transactions. The operation extends the reach of GoldFactory’s malware tooling and raises the risk of account takeover and real-time financial fraud.
Related Happenings
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware Activity
H score29
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
How related:
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally.
About this happening:
The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
ToxicPanda 2.0 Android malware expands fraud capabilities
Malware ActivityHow related: Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally.
About this happening: The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeo...
WindRelay and SpyNote RAT Android NFC relay fraud activity
Malware Activity
H score33
First: 13.08.2026 01:22
Last: 13.08.2026 01:22
Sources 1
About this happening:
The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses...
WindRelay and SpyNote RAT Android NFC relay fraud activity
Malware ActivityAbout this happening: The WindRelay and SpyNote RAT malware chain is stealing payment card data from Android devices and enabling fraudulent transactions in real time. The activity uses...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware Activity
H score20
First: 12.08.2026 17:30
Last: 12.08.2026 17:30
Sources 1
About this happening:
WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
WindRelay NFC relay malware deployed with SpyNote RAT
Malware ActivityAbout this happening: WindRelay is a previously unseen Android NFC relay malware used with SpyNote RAT in a contactless payment fraud scheme that captured live card data via NFC and rel...
RedWing Android bank-fraud malware rental service
Malware Activity
H score21
First: 07.07.2026 20:10
Last: 07.07.2026 20:10
Sources 1
About this happening:
The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
RedWing Android bank-fraud malware rental service
Malware ActivityAbout this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
Grandoreiro and BTMOB banking trojan activity targeting Windows and Android
Malware Activity
H score25
First: 27.05.2026 19:10
Last: 27.05.2026 19:10
Sources 1
About this happening:
BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...
Grandoreiro and BTMOB banking trojan activity targeting Windows and Android
Malware ActivityAbout this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...
Timeline
-
20.08.2026 13:38 2 articles · 1h ago
GoldDigger campaign spreads fake airline and shopping apps in South Africa and the U.K.
Campaign Scope UpdateGoldDigger, first documented by Group-IB in October 2023 as capable of on-device fraud, is being used in a campaign that impersonates airline companies and shopping retailers to drive a massive infection in South Africa and the U.K. Victims who install the malicious apps are urged to grant accessibility permissions, which the malware abuses to inject input into banking apps, capture credentials with fake overlays, give the operator real-time screen access, and initiate fraudulent transactions.
Show sources
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud — thehackernews.com — 20.08.2026 13:38
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud — thehackernews.com — 20.08.2026 13:38