threat-intel
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
High
Summary
ToxicPanda 2.0, an Android banking trojan, has significantly expanded its capabilities and targeting scope, now leveraging a new set of remote commands and a sophisticated overlay-based credential theft mechanism. Simultaneously, a new GoldDigger campaign, attributed to the threat actor GoldFactory, is causing widespread infections in South Africa and the U.K., impersonating airline and retail companies to facilitate on-device fraud. Both threats require users to grant excessive permissions, leading to significant risk.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
