ToxicPanda Android Malware Exploits VPN Permissions to Bypass Google Play

www.news4hackers.com-toxicpanda-android-malware-exploits-vpn-permissions-to-bypass-google-play-toxicpanda-android-malware-exploits-vpn-permissions-to-bypass-google-play

A newly identified variant of the ToxicPanda Android malware has expanded its capabilities, targeting 349 applications and incorporating 167 remote commands.

ToxicPanda 2.0 and Its Capabilities

The updated version, designated ToxicPanda 2.0, employs VPN service permissions to establish a local network interface, enabling it to manipulate traffic flow. This mechanism blocks interactions between devices and Google Play as well as Google Play Services, disrupting critical security protocols such as app verification, updates, and Play Protect communications.

The malware initiates its attack by securing VPN service permissions, which allows it to intercept and obstruct connections to Google Play. Following this, it extracts and deploys its payload before requesting Accessibility Service permissions.

Researchers at Zimperium, a mobile security firm, note that the malware is distributed via Amazon AWS-hosted buckets.

Distribution and Analysis

Analysis reveals enhanced functionality, including automated Android Wireless Debugging Bridge (ADB) operations, which grant shell-level access to compromised devices.

Phishing Overlays and PIN Harvesting

The latest iteration supports phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications across 16 countries. It also features a dedicated PIN-harvesting module targeting 140 financial and cryptocurrency apps, capable of dynamically updating its target list. These overlays operate covertly, capturing user input on affected applications.

Additionally, the malware mimics the Android lock screen to extract device PINs, patterns, and passwords. Some variants use fake system update interfaces to conceal malicious activities.

AutoBoot and Persistence Mechanisms

A specific command, autoBoot, identifies device manufacturers and activates OEM-specific auto-start or power management settings to ensure persistence. This technique bypasses battery optimization restrictions on devices from Xiaomi, OPPO, Vivo, Samsung, and Huawei.

ADB Exploitation and Shell Access

The malware’s use of ADB is notable, as it exploits Accessibility Service permissions to enable Developer Options and activate Wireless Debugging. It then retrieves the six-digit ADB pairing code and port, establishing a connection with the device’s local ADB service. Once shell access is achieved, the malware executes high-privilege commands through the ADB daemon, circumventing standard Android consent prompts. This allows it to bypass background process restrictions, activate critical components silently, and maintain persistence.

Zimperium highlights that Wireless ADB abuse is becoming prevalent among Android malware, with similar implementations observed in the RedHook malware.

Blue Report 2026 Findings

Research conducted by the Blue Report 2026, which analyzed 338 million simulations across customer environments, found that 63% of attacker actions remain undetected even with valid credentials. The report evaluates defensive measures across various techniques.

Evolving Threats and Recommendations

The malware’s ability to manipulate device functions underscores the evolving tactics of threat actors targeting mobile ecosystems. Security professionals are advised to monitor for signs of unauthorized ADB activity and implement robust endpoint protections to mitigate risks associated with such threats.



About Author

en_USEnglish