Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

ToxicPanda 2.0 & GoldDigger Expand Android Banking Malware – PIN Harvesting Across 140+ Apps

Zimperium zLabs reports ToxicPanda 2.0 now carries 167 remote commands and a PIN‑harvesting workflow targeting over 140 banking and crypto Android apps, highlighting a credential‑compromise risk that SOC 2 access‑control controls must address.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

ToxicPanda 2.0 & GoldDigger Amplify Android Banking Malware – PIN Harvesting Across 140+ Apps

What Happened — Researchers at Zimperium zLabs disclosed an upgraded Android malware family, ToxicPanda 2.0 (aka TgToxic), now equipped with 167 remote commands and a dedicated PIN‑harvesting workflow. The payload targets more than 140 banking and cryptocurrency applications worldwide, expanding the on‑device fraud surface for mobile users.

Why It Matters for Compliance & Audit Readiness

  • The campaign illustrates a classic credential‑compromise scenario that SOC 2 Access Controls (CC6.1, CC6.2) are designed to prevent and evidence.
  • Continuous monitoring of mobile device security and user‑behavior analytics provides the audit‑ready logs needed to demonstrate “least‑privilege” and “monitoring” controls.
  • Security Awareness Training that includes mobile‑phishing and on‑device fraud mitigations helps satisfy the “Security Awareness” sub‑criteria of SOC 2 (CC7.1).

Who Is Affected — Financial services, cryptocurrency platforms, and any SaaS providers whose customers use Android banking apps.

Recommended Actions

  • Map the threat to SOC 2 Access Control criteria (CC6.1/CC6.2) and ensure you have documented mobile device management (MDM) policies.
  • Deploy continuous endpoint telemetry and integrate logs into your compliance evidence repository.
  • Refresh security‑awareness curricula to cover Android‑specific credential‑theft techniques and PIN‑harvesting tactics.

Source: The Hacker News

Technical Notes

  • Attack vector: malicious Android APKs delivered via third‑party app stores and phishing links.
  • Capabilities: 167 remote commands, PIN‑harvesting module, command‑and‑control (C2) over HTTPS.
  • No public CVE; the threat leverages social engineering and mobile OS weaknesses rather than a disclosed software flaw.
📰 Original Source
https://thehackernews.com/2026/08/toxicpanda-20-and-golddigger-expand.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →