Cybersecurity researchers have identified a heavily updated variant of the ToxicPanda Android malware, alongside a related toolkit dubbed GoldDigger. The new version, tracked as ToxicPanda 2.0, introduces 167 remote commands and an automated workflow designed to steal personal identification numbers (PINs) from users of 349 financial institutions globally.
This iteration marks a tactical shift from earlier versions that relied on intercepting network traffic or exploiting operating system vulnerabilities. Instead, the malware operates directly on compromised handsets by abusing Android’s accessibility services and screen overlay functions. By generating fraudulent login prompts and logging keystrokes locally, it can capture credentials and bypass multi-factor authentication without triggering network-based security alerts.
Analysis of the malware reveals a command-and-control infrastructure distributed across multiple jurisdictions to complicate tracking and law enforcement intervention. Operators have also moved away from official app stores, relying instead on sideloaded applications and social engineering to bypass platform security reviews. This distribution model shifts the primary detection burden to enterprise mobile security teams and endpoint management systems.
Security teams are advised to move beyond traditional network monitoring and implement runtime-focused defenses. Recommended mitigations include enforcing strict application allowlisting, configuring mobile device management (MDM) policies to block unauthorized sideloading, and deploying monitoring tools that detect abnormal accessibility API usage or unauthorized screen overlays. Integrating updated threat intelligence, including indicators of compromise and behavioral signatures, remains essential for maintaining visibility across corporate device fleets.
The malware’s exploitation of legitimate system permissions highlights ongoing gaps in mobile endpoint security. The industry currently lacks standardized, vendor-agnostic security benchmarks for detecting these specific abuse patterns. Additionally, the cross-border nature of the command-and-control servers underscores the need for formalized international intelligence sharing to coordinate infrastructure takedowns. Researchers are urging Android platform maintainers to publish a public roadmap outlining stricter auditing for accessibility services and enhanced application sandboxing to prevent future exploitation.
As financial institutions continue to consolidate authentication and transaction workflows on mobile devices, the evolution of ToxicPanda and GoldDigger illustrates the growing threat of on-device manipulation. Organizations managing corporate mobile environments will need to prioritize runtime visibility and enforce strict application controls to mitigate direct compromise attempts.
網絡安全研究人員發現 Android 惡意軟件 ToxicPanda 的大幅更新版本,以及名為 GoldDigger 的相關工具包。被追蹤為 ToxicPanda 2.0 的新版本引入 167 項遠端指令及自動化工作流程,旨在竊取全球 349 間金融機構用戶的個人識別碼(PIN)。
此版本標誌著戰術上的轉變。過往版本主要依賴攔截網絡流量或利用操作系統漏洞,而新變種則改為直接在受感染手機上運作,濫用 Android 的 accessibility services 及螢幕覆蓋層功能。透過在本地生成虛假登入提示及記錄按鍵輸入,該惡意軟件能擷取憑證並繞過 multi-factor authentication,且不會觸發基於網絡的安全警報。
分析顯示,該惡意軟件的 command-and-control (C2) 基礎設施分散於多個司法管轄區,以增加追蹤及執法部門介入的難度。營運者亦已放棄官方應用程式商店,轉而依賴 sideloading 應用程式及社會工程學手法繞過平台安全審查。此分發模式將主要的偵測責任轉移至企業的流動保安團隊及端點管理系統。
建議保安團隊超越傳統網絡監控,實施以 runtime 為核心的防禦措施。建議的緩解方案包括執行嚴格的應用程式 allowlisting、設定 MDM 政策以阻止未經授權的 sideloading,以及部署能偵測異常 accessibility API 使用或未經授權螢幕覆蓋層的監控工具。整合最新的 threat intelligence(包括 indicators of compromise 及 behavioral signatures),對於維持企業裝置群的監控覆蓋率依然至關重要。
該惡意軟件對合法系統權限的利用,突顯了流動端點保安持續存在的缺口。業界目前缺乏標準化且不依賴特定供應商的保安基準,以偵測此類特定的濫用模式。此外,C2 伺服器的跨境性質亦凸顯了建立正式國際情報共享機制的必要性,以便協調取締相關基礎設施。研究人員敦促 Android 平台維護者公佈公開路線圖,列明對 accessibility services 實施更嚴格審核及強化應用程式 sandboxing 的計劃,以防範未來遭利用。
隨著金融機構持續將驗證及交易工作流程集中於流動裝置,ToxicPanda 與 GoldDigger 的演變說明了裝置端操控的威脅日益增加。管理企業流動環境的機構必須將 runtime visibility 列為優先事項,並執行嚴格的應用程式控制,以減低直接入侵企圖帶來的風險。
