ToxicPanda Android malware uses VPN permissions to block Google Play

ToxicPanda Android malware uses VPN permissions to block Google Play

ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 apps and adding support for 167 remote commands.

Malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature allows ToxicPanda 2.0 to block communication from Google Play and Google Play Services.

Network-level control allows malware to interfere with various security checks and actions, such as app checks, updates, Play Protect communication, or legitimate outages designed to protect users.

image

After obtaining VPN service permissions, ToxicPanda 2.0 blocks communications to Google Play before extracting and installing its payload, then requests accessibility service permissions.

Cimperium
Source: Zimperium

Mobile security company Zimperium says ToxicPanda 2.0 is distributed through buckets hosted by Amazon AWS.

Analysis of the malware revealed that it now includes features to automate the Android Wireless Debugging Bridge (ADB), allowing shell-level access to infected devices.

The latest version of the malware supports 167 remote commands and phishing overlays for 349 banking, finance, cryptocurrency and e-wallet apps targeting 16 countries.

It also includes a separate PIN collection module that targets 140 financial and cryptocurrency applications and can dynamically update the target list.

According to the researchers, app overlays are invisible to the victim, allowing the malware to capture touch input on targeted apps.

ToxicPanda also spoofs the Android lock screen to capture device PINs, unlock patterns, and passwords.

Some analyzed malware samples also used fake system update screens to hide ongoing malicious activity.

Fake update overlays
Fake update overlays used by ToxicPanda
Source: Zimperium

One command, “autoBoot”, identifies the host device manufacturer and initiates the appropriate OEM-specific autoboot or power management settings to maintain persistence.

Zimperium reports that this bypasses battery drain protections that kill background processes on Xiaomi, OPPO, Vivo, Samsung and Huawei devices.

Abusing ADB

One feature that stands out in the recent release of Toxic Panda analyzed is its automatic abuse of the Android Debug Bridge (ADB) to gain shell access.

ADB is the command line tool for executing shell commands on Android devices. Wireless ADB, introduced in Android 11, provides this access over Wi-Fi without a USB connection.

Using the Accessibility Services permission, the malware enables developer options, enables wireless debugging, retrieves the six-digit ADB pairing code and port, and connects to the device’s local ADB service.

Cimperium
Source: Zimperium

“Once the malware obtains user shell permissions, it starts executing high-privilege commands directly through the ADB daemon, the malware bypasses standard Android runtime consent prompts to grant itself broad permissions, neutralize background OS restrictions, silently enable critical components, and enforce persistence,” Zimperium explains.

Wireless ADB abuse is a growing trend among Android malware as other Android malware authors have implemented it in their malicious tools. Recently, Group-IB reported a similar mechanism implemented in the latest version of the RedHook malware.

Zimperium published a list of Indicators of Compromise (IoC) associated with the latest version of ToxicPanda in the this GitHub repository.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *