ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
An upgraded version of ToxicPanda (also known as TgToxic) with "significant enhancements," such as a set of 167 remote instructions and an expanded worldwide targeting area, has been revealed by cybersecurity researchers.
The Android virus also has a PIN harvesting methodology that targets over 140 banking and cryptocurrency applications, according to a research published on Wednesday by Zimperium zLabs. Since at least July 2022, ToxicPanda has been known to be active in the wild.
In addition to an overlay-based credential theft mechanism that targets 349 financial institutions [across 16 countries], threat actors can steal every user interface element on the screen by abusing the Android accessibility service. The latest version shows a significant expansion in targeting scope and ...

