Skip to content
Tech News
← Back to articles

ToxicPanda Android malware uses VPN permissions to block Google Play

read original more articles
Why This Matters

The evolution of ToxicPanda Android malware to include VPN permissions and network control capabilities significantly enhances its ability to evade detection and disrupt security measures, posing a serious threat to user privacy and device security. Its widespread targeting of banking and financial apps underscores the increasing sophistication of mobile malware and the need for robust security defenses in the industry and for consumers.

Key Takeaways

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.

The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services.

Control at the network level permits the malware to interfere with various security checks and actions, such as app verifications, updates, Play Protect communication, or legitimate disruptions designed to protect users.

After obtaining VPN service permissions, ToxicPanda 2.0 blocks communications to Google Play before extracting and installing its payload, then requests Accessibility Service permissions.

Source: Zimperium

Mobile security company Zimperium says that ToxicPanda 2.0 is being distributed through Amazon AWS-hosted buckets.

Analysis of the malware revealed that it now includes functions to automate the Android Wireless Debugging Bridge (ADB), enabling shell-level access to infected devices.

The latest version of the malware supports 167 remote commands and phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications targeting 16 countries.

It also includes a separate PIN-harvesting module that targets 140 financial and cryptocurrency apps and can dynamically update the target list.

According to the researchers, the app overlays are invisible to the victim, allowing the malware to capture touch inputs on targeted apps.

... continue reading