The ToxicPanda Android malware has gained new ways to interfere with security features, steal banking data and retain control of infected phones. Researchers say the updated threat blocks Google Play traffic through a local VPN interface before installing its main payload.
ToxicPanda uses VPN access to block Google services
Researchers at Zimperium found that ToxicPanda 2.0 begins by requesting Android VPN service permissions through a fake installation screen.
Once the user grants access, the malware creates a local VPN interface and blocks communication with Google Play and Google Play Services. This could disrupt app verification, updates, Play Protect checks and other security actions.
The malware then decrypts and installs its hidden payload. Afterward, it prompts the victim to enable Android Accessibility Services.
Zimperium says the latest samples are distributed through Amazon AWS-hosted buckets.
Malware targets hundreds of financial apps
ToxicPanda Android malware now supports phishing overlays for 349 banking, financial, e-wallet and cryptocurrency apps across 16 countries.
When a victim opens a targeted app, the malware can request a matching fake screen from its command-and-control server. These overlays imitate genuine login or payment pages and aim to steal credentials, PINs and other sensitive information.
The updated version also contains a PIN-harvesting module for more than 140 financial and cryptocurrency apps. It can update its target list remotely.
Researchers said the malware can use an invisible overlay to capture touch input inside targeted apps. It can also imitate the Android lock screen to steal device PINs, passwords and unlock patterns.
Wireless ADB abuse gives attackers shell access
One of ToxicPanda’s most serious new features is its ability to abuse Wireless Debugging, also known as wireless ADB.
Using Accessibility permissions, the malware can enable Developer Options and turn on Wireless Debugging. It then extracts the pairing code and port from the Android interface before connecting to the device’s local ADB service.
This gives attackers shell-level access. They can use it to grant additional permissions, bypass background restrictions, enable malicious components and strengthen persistence.
Fake updates help hide malicious activity
Some ToxicPanda samples display fake full-screen system update pages while the malware runs in the background. These deceptive screens help hide its activity from users.
The malware also includes commands that target battery and auto-start settings on Xiaomi, OPPO, Vivo, Samsung and Huawei devices. By changing these settings, it can avoid Android power-management controls that would otherwise stop its background processes.
The expanded ToxicPanda Android malware shows how threat actors can combine VPN permissions, accessibility abuse and Wireless Debugging to take deeper control of Android devices.
Users should avoid installing apps from unofficial sources, deny unexpected VPN or accessibility requests and keep Google Play Protect enabled.


0 responses to “ToxicPanda Android Malware Blocks Google Play With VPN Access”