Protect.Computer
NEWS

ToxicPanda Android Malware Uses VPN to Silence Google Play

· 1 min read · Malicious byte Device safety
ToxicPanda Android Malware Uses VPN to Silence Google Play

A significantly upgraded version of the ToxicPanda Android banking trojan has emerged with a novel defense-evasion technique: it requests VPN service permissions to intercept and block all traffic to Google Play and Google Play Services. By cutting off Play Protect, app verification requests, and security updates at the network layer, the malware creates a window to install its payload and request Accessibility Service permissions before Google’s defenses can react.

Researchers at Zimperium found that ToxicPanda 2.0 is being distributed through malware-laced APKs hosted on Amazon AWS buckets, often disguised behind fake system-update overlays. Once installed, the malware supports 167 remote commands and deploys phishing overlays against 349 banking, financial, cryptocurrency, and e-wallet applications across 16 countries. A separate PIN-harvesting module quietly captures unlock patterns, PINs, and passwords from 140 financial apps. The malware also abuses Android’s Wireless Debugging Bridge (ADB) to gain shell-level access, letting it bypass battery management controls and maintain persistence on devices from Xiaomi, OPPO, Vivo, Samsung, and Huawei.

How to check if you’re affected

Affected devices are Android smartphones — particularly from Xiaomi, OPPO, Vivo, Samsung, and Huawei — where users have installed apps from outside the Google Play Store. To check: open Settings → Network → VPN and look for any VPN you did not set up yourself. Open Settings → Accessibility and review which apps have Accessibility access enabled — remove anything unfamiliar. If you are using any banking, crypto, or e-wallet app, verify it was installed directly from Google Play and not sideloaded from a third-party source.

Sources

Related reading