ToxicPanda 2.0 malware blocks Google Play traffic via VPN to install payloads
The ToxicPanda 2.0 Android malware strain now blocks Google Play traffic through VPN permissions to install malicious payloads undetected, mobile security firm Zimperium reported.
Source: BleepingComputer · August 23, 2026 at 5:31 PM · AI-assisted report
Single-sourceKUALA LUMPUR, 24 AUGUST 2026 —
The ToxicPanda 2.0 Android malware strain now blocks Google Play traffic through VPN permissions to install malicious payloads undetected, mobile security firm Zimperium reported.
Market Impact
The new variant targets 349 applications and supports 167 remote commands, up from earlier builds. After gaining VPN rights, it cuts off Google Play and Play Services communications before dropping its payload. Zimperium said the malware is hosted on Amazon AWS buckets and uses overlays invisible to victims to capture touch inputs on banking, financial, cryptocurrency and e-wallet apps across 16 countries.
Once VPN control is established, ToxicPanda interferes with security checks such as app verifications, updates and Play Protect messages. The malware later requests Accessibility Service permissions to begin harvesting PINs, unlock patterns and passwords. Spoofed lock screens and fake system update pages hide ongoing activity, while a PIN-harvesting module separately targets 140 financial and crypto apps and can update targets dynamically.
A standout feature is automatic abuse of the Android Debug Bridge. Wireless ADB, introduced in Android 11, lets the malware enable Developer Options, turn on Wireless Debugging and extract pairing codes without physical access. Zimperium noted this grants shell-level access that bypasses Android runtime consent prompts and neutralises OS background restrictions on devices from Xiaomi, OPPO, Vivo, Samsung and Huawei.
The malware uses an autoBoot command to launch OEM-specific auto-start settings and maintain persistence despite battery optimisation protections. Zimperium said this technique mirrors recent abuse by other families such as RedHook. The company has published indicators of compromise on GitHub.
Related: Google