ToxicPanda 2.0 Expands Android Targeting and Uses VPN Access to Disrupt Google Services

The ToxicPanda Android banking malware has gained new capabilities that give it greater control over infected devices, according to an analysis by mobile security company Zimperium. The latest version...

The ToxicPanda Android banking malware has gained new capabilities that give it greater control over infected devices, according to an analysis by mobile security company Zimperium. The latest version, identified as ToxicPanda 2.0, targets 349 applications and supports 167 commands that can be issued remotely.

One notable addition is the abuse of Android’s VPN service permissions. After obtaining access, the malware creates a local VPN interface and routes device traffic through it. This allows ToxicPanda to block connections to Google Play and Google Play Services before deploying additional components and requesting Accessibility Service access.

Disrupting Google’s services could interfere with application verification, updates, Play Protect communications, and other checks that may detect or limit malicious activity. Zimperium said samples have been distributed from storage buckets hosted on Amazon Web Services.

Banking and credential theft features

The malware uses phishing overlays against banking, financial, cryptocurrency, and digital-wallet applications in 16 countries. Researchers also identified a separate module aimed at collecting PINs from 140 financial and cryptocurrency apps. The target list can reportedly be updated by the attackers.

Some overlays are designed to remain hidden while still capturing touch input. ToxicPanda can also imitate the Android lock screen to steal device PINs, patterns, and passwords. Fake system-update screens have been observed concealing activity while the malware operates in the background.

Wireless ADB abuse

ToxicPanda 2.0 can automate Android Wireless Debugging, a feature available since Android 11 that provides ADB access over Wi-Fi. Using Accessibility permissions, the malware enables Developer Options, turns on Wireless Debugging, retrieves the pairing code and port, and connects to the device’s local ADB service.

With shell-level access, it can execute commands through the ADB daemon, bypass certain runtime permission prompts, grant itself additional privileges, weaken background-process restrictions, and enable components needed for persistence. A command named autoBoot adjusts manufacturer-specific startup and battery settings on devices from vendors including Xiaomi, OPPO, Vivo, Samsung, and Huawei.

Zimperium has published indicators of compromise for the campaign in a GitHub repository. Users should avoid installing apps from unofficial sources, scrutinize requests for VPN or Accessibility permissions, and keep Android and security software updated.