ToxicPanda banking trojan updated to abuse VPN permissions and block Google Play
Zimperium researchers found a new version of the ToxicPanda Android malware that requests VPN service permissions to intercept and control device network traffic, allowing it to cut off communication with Google Play and Play Protect. The updated trojan, spread via Amazon AWS-hosted buckets, now supports 167 remote commands and phishing overlays for 349 banking, crypto, and e-wallet apps across 16 countries, plus a separate module that harvests PINs from 140 financial apps.