ToxicPanda 2.0 Android malware expands fraud capabilities
Malware Activity
Summary
Hide ▲
Show ▼
The ToxicPanda (aka TgToxic) Android malware family now ships with 167 remote commands and broader fraud features that raise the risk of credential theft and account takeover. The updated build adds PIN harvesting for 140+ banking and cryptocurrency apps and extends overlay-based theft against 349 financial institutions across 16 countries. It abuses the Android accessibility service and Wireless Debugging/ADB to gain privilege escalation and shell-level access. Delivery has also shifted to Amazon AWS-hosted buckets, and the family has been active since at least July 2022.
Related Happenings
GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
Campaign
H score41
First: 20.08.2026 13:38
Last: 20.08.2026 13:38
Sources 1
How related:
The current GoldDigger campaign mainly impersonates airline companies and shopping retailers, resulting in a "massive infection" in South Africa and the U.K.
About this happening:
A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigge...
GoldFactory GoldDigger Android banking campaign targeting South Africa and the U.K.
CampaignHow related: The current GoldDigger campaign mainly impersonates airline companies and shopping retailers, resulting in a "massive infection" in South Africa and the U.K.
About this happening: A GoldDigger Android banking campaign is driving mass infections in South Africa and the U.K., using fake airline and shopping apps to steal credentials and trigge...
Manic Android malware activity with offline relay exfiltration
Malware Activity
H score27
First: 20.08.2026 13:02
Last: 20.08.2026 13:02
Sources 1
About this happening:
The Manic Android malware is active across multiple European countries, with Ukraine as its main focus, and its fallback exfiltration path can keep data moving eve...
Manic Android malware activity with offline relay exfiltration
Malware ActivityAbout this happening: The Manic Android malware is active across multiple European countries, with Ukraine as its main focus, and its fallback exfiltration path can keep data moving eve...
ToxicPanda 2.0 Android banking trojan expansion
Malware Activity
H score28
First: 20.08.2026 13:00
Last: 20.08.2026 13:00
Sources 1
About this happening:
The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
ToxicPanda 2.0 Android banking trojan expansion
Malware ActivityAbout this happening: The ToxicPanda 2.0 Android banking trojan now steals PINs and overlay credentials, widening its reach to 140 banking and cryptocurrency apps and 349 financial in...
RedWing Android spyware rented through Telegram
Malware Activity
H score21
First: 08.07.2026 18:30
Last: 08.07.2026 18:30
Sources 1
About this happening:
The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android spyware rented through Telegram
Malware ActivityAbout this happening: The RedWing Android spyware operation is being rented through Telegram, lowering the barrier for criminals to hijack phones and steal banking credentials. The malware...
RedWing Android bank-fraud malware rental service
Malware Activity
H score21
First: 07.07.2026 20:10
Last: 07.07.2026 20:10
Sources 1
About this happening:
The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
RedWing Android bank-fraud malware rental service
Malware ActivityAbout this happening: The RedWing Android malware service is being rented on Telegram to steal banking logins, OTPs, and device control, raising fraud risk for banking and cryptocurre...
Timeline
-
20.08.2026 13:38 2 articles · 1h ago
ToxicPanda 2.0 adds 167 commands and expands Android fraud targeting
Technical Analysis UpdateResearchers described an updated ToxicPanda (aka TgToxic) Android malware build that adds 167 remote commands, uses PIN harvesting against more than 140 banking and cryptocurrency apps, and broadens overlay-based credential theft to 349 financial institutions across 16 countries. The malware abuses Android accessibility services and Android Wireless Debugging via Android Debug Bridge (ADB) to enable privilege escalation and shell-level access, establishes a bidirectional WebSocket C2 channel after an initial HTTPS request, and is now delivered through Amazon AWS-hosted buckets; ToxicPanda has been active in the wild since at least July 2022.
Show sources
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud — thehackernews.com — 20.08.2026 13:38
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud — thehackernews.com — 20.08.2026 13:38