459/69 Monday, August 24, 2026
Security researchers have disclosed ToxicPanda 2.0, an Android malware strain that has added the ability to request VPN Service permissions to create a local interface for controlling network traffic on infected devices. This feature allows the malware to block communications from Google Play and Google Play Services, potentially interfering with app verification, updates, and Play Protect communications that help protect users from malicious applications.
ToxicPanda 2.0 is distributed through a bucket hosted on Amazon AWS and supports 167 control commands, including phishing overlays targeting 349 banking, financial, cryptocurrency, and e-wallet applications across 16 countries. It also includes a PIN-stealing module targeting more than 140 financial and cryptocurrency applications. The target list can be updated dynamically, and the malware uses invisible overlays to capture screen taps on targeted applications.
The malware can automatically use Android Debug Bridge (ADB) to obtain shell-level privileges on the device by abusing Accessibility permissions to enable Developer Options, turn on Wireless Debugging, extract the six-digit ADB pairing code and port number, and connect to the ADB service inside the device. Once shell privileges are obtained, the malware can execute higher-privileged commands, grant itself additional permissions, disable background execution restrictions, activate key components without notification, and establish persistence mechanisms. Android users should install applications only from official sources and avoid granting VPN Service, Accessibility Service, or Wireless Debugging permissions to applications that do not require them.
