Fake Airline Apps Push Android Banking Fraud

The Hacker News · High sophistication
Last updated August 20, 2026

Researchers report two Android banking malware families (ToxicPanda 2.0 and GoldDigger) that rely on tricking people into installing malicious apps and granting powerful permissions. GoldDigger campaigns impersonate airlines and shopping retailers and then abuse Android Accessibility to take over banking apps and initiate fraudulent transfers from the victim’s device.

Key findings

  • ToxicPanda 2.0 adds a PIN-harvesting workflow and uses overlays plus Android Accessibility abuse to capture on-screen data and credentials.
  • ToxicPanda 2.0 can show full-screen “system update” overlays to hide background actions and can trick victims into granting Device Administrator privileges.
  • Zimperium says ToxicPanda 2.0 distribution shifted to “Amazon AWS-hosted buckets,” suggesting cloud hosting is used for delivery.
  • GoldDigger campaigns “impersonate airline companies and shopping retailers,” leading to widespread infections in South Africa and the U.K.
  • After installation, victims are prompted to grant Accessibility permissions, which the malware then uses to mimic user actions inside banking apps and initiate fraudulent transactions.
  • GoldDigger can also use overlays to capture credentials and provide real-time screen access to operators.

Who’s being targeted

  • Commonly targeted roles: All employees (Android users), Finance teams (high-risk for fraud impacts), Executives, Frequent travelers, Anyone who uses mobile banking or crypto apps.
  • Affected industries: Finance (banking), Cryptocurrency/financial services, Airlines (impersonated brand), Retail/e-commerce (impersonated brand).
  • Attack channels: website.
  • Impersonated: Airline company or shopping retailer (brand impersonation), Android system update, A legitimate-looking app/system permission prompt.

Awareness takeaways

  • Treat ‘permission prompts’ (especially Accessibility and Device Administrator) as a major warning sign and deny them unless there is a clear business need.
  • Be skeptical of unexpected ‘system update’ screens or overlays, stop and verify rather than continuing to enter PINs or credentials.
  • Only install mobile apps from trusted sources/developers and remove unfamiliar apps quickly.
  • Monitor bank accounts for unusual transactions because these threats can initiate transfers directly from the banking app on the phone.

Red flags to watch for

  • App requests Accessibility permissions unrelated to its purpose
  • App is not from a trusted developer/source
  • Unexpected overlays or behavior after installation
  • Unexpected full-screen ‘system update’ screen at unusual times
  • Device behaves oddly while an ‘update’ is supposedly running
  • Prompts that don’t look like standard Android update flows
  • Unfamiliar app requesting Device Administrator privileges
  • Permission request doesn’t match the app’s purpose
  • Pressure to approve privileges to proceed
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You install a “special offer” airline app… and ten minutes later, money is moving out of your banking app by itself. That’s GoldDigger and ToxicPanda 2.0, Android banking malware hiding in fake airline and shopping apps, often hosted on Amazon AWS buckets. After install, they pop up a friendly message: “To work properly, please enable Accessibility services.” Here’s the nasty part: once you tap Allow, they abuse Accessibility to mimic your taps inside banking apps, use overlays to steal your PIN, and even throw up a full-screen fake “System update in progress” to hide what’s really happening. Your move: if any airline or shopping app asks for Accessibility or Device Administrator, stop right there and deny it, no exception.

Similar attacks

Gigabud Hides Fake Bank App in Android Work Profile

Gigabud Hides Fake Bank App in Android Work Profile

Researchers say the Gigabud banking trojan is being installed via fake apps (e.g., pretending to be an airline, tax office, or government portal) and then uses an Android “work profile” to hide a tampered banking app. Victims are tricked into granting powerful permissions, after which attackers can…

September 10, 2026
Handala Uses Fake “Support” Chats to Drop Malware

Handala Uses Fake “Support” Chats to Drop Malware

Researchers linked the Iran-aligned Handala Hack persona to a Telegram-controlled backdoor (HEAVYGRAM) that can steal passwords and exfiltrate chat data. The campaign reportedly starts with social engineering on messaging apps (Telegram, WhatsApp, Instagram), where the attacker pretends to offer…

September 18, 2026
RatHat Smishing Lure Pushes Android Sideloading

RatHat Smishing Lure Pushes Android Sideloading

Researchers described an Android Trojan (“RatHat”) that starts with scam texts or malicious ads and tricks people into installing a fake app from a bogus download page. After installation, it pressures victims to grant Accessibility permissions using fake excuses or incentives, then uses those…

September 18, 2026
Gigabud Clones Banking Apps in Hidden Work Profile

Gigabud Clones Banking Apps in Hidden Work Profile

Researchers say the Android banking Trojan “Gigabud” can trick victims into installing a fake app, then create a separate Android work profile and run a cloned banking app inside it. Attackers can perform fraudulent transactions from that cloned app, which may reduce the chance that bank defenses…

September 11, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
ToxicPanda 2.0 Tricks Users, Steals Bank Logins

ToxicPanda 2.0 Tricks Users, Steals Bank Logins

Zimperium reports ToxicPanda 2.0 is a mobile banking trojan that targets 349 financial apps across 16 countries by impersonating legitimate screens and prompts to trick users into granting permissions. After installation, it uses Android Accessibility and Wireless Debugging to gain deeper control…

August 22, 2026