Close Menu
NCIJ Network NCIJ Network
    What's Hot

    DR Congo and M23 rebels agree roadmap for peace talks

    August 23, 2026

    Zelenskyy: Elections would ‘tear Ukraine apart’ – POLITICO

    August 23, 2026

    The Midterms Feel Like 2006 All Over Again

    August 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • DR Congo and M23 rebels agree roadmap for peace talks
    • Zelenskyy: Elections would ‘tear Ukraine apart’ – POLITICO
    • The Midterms Feel Like 2006 All Over Again
    • We’re All Going to the World’s Fair is an intimate coming-of-age horror film
    • Robot Brains Could Have Their ‘ChatGPT Moment’ by 2027, ACE Robotics Chairman Says
    • Patricio Segura, journalist who defended Patagonia’s rivers, has died of hantavirus at 54
    • Spying device detectors may give domestic abuse victims false sense of security, study finds | Domestic violence
    • Onshore windfarm applications hit 10-year high in England | Wind power
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, August 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ToxicPanda Android malware uses VPN permissions to block Google Play

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 23, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands.

    The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services.

    Control at the network level permits the malware to interfere with various security checks and actions, such as app verifications, updates, Play Protect communication, or legitimate disruptions designed to protect users.

    image

    After obtaining VPN service permissions, ToxicPanda 2.0 blocks communications to Google Play before extracting and installing its payload, then requests Accessibility Service permissions.

    Zimperium
    Source: Zimperium

     

    Mobile security company Zimperium says that ToxicPanda 2.0 is being distributed through Amazon AWS-hosted buckets.

    Analysis of the malware revealed that it now includes functions to automate the Android Wireless Debugging Bridge (ADB), enabling shell-level access to infected devices.

    The latest version of the malware supports 167 remote commands and phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications targeting 16 countries.

    It also includes a separate PIN-harvesting module that targets 140 financial and cryptocurrency apps and can dynamically update the target list.

    According to the researchers, the app overlays are invisible to the victim, allowing the malware to capture touch inputs on targeted apps.

    ToxicPanda also spoofs the Android lock screen to capture device PINs, unlocking patterns, and passwords.

    Some analyzed malware samples also used fake system update screens to hide ongoing malicious activity.

    Fake update overlays
    Fake update overlays used by ToxicPanda
    Source: Zimperium

    One command, ‘autoBoot,’ identifies the host device manufacturer and launches the corresponding OEM-specific auto-start or power management settings to maintain persistence.

    Zimperium reports that this bypasses battery consumption protections that kill background processes on Xiaomi, OPPO, Vivo, Samsung, and Huawei devices.

    Abusing ADB

    One feature that stands out in the analyzed recent Toxic Panda version is its automatic abuse of the Android Debug Bridge (ADB) to gain shell access.

    ADB is the command-line tool for executing shell commands on Android devices. Wireless ADB, introduced in Android 11, provides this access over Wi-Fi without a USB connection.

    Using the Accessibility Services permission, the malware enables Developer Options, activates Wireless Debugging, extracts the six-digit ADB pairing code and port, and connects with the device’s local ADB service.

    Zimperium
    Source: Zimperium

    “Once the malware gains shell user permissions, it starts executing high-privilege commands directly through the ADB daemon, the malware bypasses standard Android runtime consent prompts to grant itself broad permissions, neutralize OS background restrictions, silently enable critical components, and enforce persistence,” Zimperium explains.

    Wireless ADB abuse is a growing trend among Android malware, as other Android malware authors have implemented it in their malicious tools. Recently, Group-IB reported a similar mechanism implemented in the latest version of the RedHook malware.

    Zimperium has published a list of indicators of compromise (IoCs) associated with the latest ToxicPanda version in this GitHub repository.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Android block Google Malware Permissions play ToxicPanda VPN
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    How you can stop Google AI from accessing your Gmail, chat information

    Hardware Makers Implement Post-Quantum Cryptography

    Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

    CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

    Why “Shady AI” is Security’s Next Big Governance Problem

    Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    DR Congo and M23 rebels agree roadmap for peace talks

    August 23, 2026

    Zelenskyy: Elections would ‘tear Ukraine apart’ – POLITICO

    August 23, 2026

    The Midterms Feel Like 2006 All Over Again

    August 23, 2026

    We’re All Going to the World’s Fair is an intimate coming-of-age horror film

    August 23, 2026
    Latest Posts

    Little Italy group, city of San Diego at ‘stalemate’ over bike lane

    July 28, 2026

    Blazing like 10 billion suns: NASA’s Swift sees a wandering black hole devouring a star

    July 28, 2026

    Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    DR Congo and M23 rebels agree roadmap for peace talks

    August 23, 2026

    Zelenskyy: Elections would ‘tear Ukraine apart’ – POLITICO

    August 23, 2026

    The Midterms Feel Like 2006 All Over Again

    August 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.