ToxicPanda Android malware uses VPN permissions to block Google Play

ToxicPanda Android malware uses VPN permissions to block Google Play
ToxicPanda Android malware has evolved into a more capable threat, expanding its targeting to 349 apps and adding 167 remote commands while using VPN permissions to block Google Play traffic and install its payload. Zimperium says ToxicPanda 2.0 is spread via Amazon AWS-hosted buckets, abuses Accessibility Services and Wireless ADB for shell access, and uses overlays and fake screens to steal PINs and credentials across 16 countries. #ToxicPanda #Zimperium #GooglePlay #WirelessADB #AmazonAWS

Keypoints

  • ToxicPanda 2.0 now targets 349 banking, financial, cryptocurrency, and e-wallet apps.
  • The malware supports 167 remote commands and a dedicated PIN-harvesting module.
  • It requests VPN service permissions to block Google Play and Google Play Services traffic.
  • ToxicPanda abuses Accessibility Services and Wireless ADB to gain shell-level access.
  • It uses invisible overlays, fake updates, and lock screen spoofing to steal sensitive credentials.

Read More: https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/