logo

ToxicPanda Android malware uses VPN permissions to block Google Play

ID: dcbd9049-5cc4-5094-8769-f4d8da30cd26

STIX ID: report--dcbd9049-5cc4-5094-8769-f4d8da30cd26

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-08-23

Date Updated: 2026-08-23

Author: Bill Toulas

...
...

ToxicPanda 2.0 is an evolved Android banking malware distributed via AWS-hosted buckets that now requests VPN permissions to block Google Play/Play Services, abuses Accessibility Services to enable wireless ADB for shell-level access, and deploys invisible phishing overlays and PIN-harvesting modules targeting hundreds of financial and crypto apps across multiple countries; researchers (Zimperium) published IoCs and detailed persistence and anti-detection techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.