ToxicPanda now targets 349 applications and supports 167 remote commands, according to mobile security researchers.
VPN permissions and blocking Google Play
The latest ToxicPanda variant asks for Android VPN service permissions to create a local network interface that lets it control traffic passing through the device. Using that local interface, the malware blocks communication to Google Play and Google Play Services before extracting and installing its payload and then requests Accessibility Service permissions. By operating at the network layer, ToxicPanda 2.0 can interfere with app verifications, updates, Play Protect communication and other security checks that rely on network connectivity, the researchers report.
Abusing the Android Debug Bridge (ADB)
A notable capability in the analyzed samples is automated abuse of Android Debug Bridge (ADB). ToxicPanda 2.0 uses Accessibility Services to enable Developer Options, turn on Wireless Debugging, extract the six-digit ADB pairing code and port, and connect to the device’s local ADB service. Zimperium documents the consequence plainly: “Once the malware gains shell user permissions, it starts executing high-privilege commands directly through the ADB daemon, the malware bypasses standard Android runtime consent prompts to grant itself broad permissions, neutralize OS background restrictions, silently enable critical components, and enforce persistence.”
The researchers note Wireless ADB abuse is a growing trend; Group-IB recently reported a similar mechanism implemented in the RedHook malware.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleInvisible overlays, PIN-harvesting, and fake system screens
ToxicPanda 2.0 carries extensive fraud and credential-theft tooling. The samples analyzed include phishing overlays that target 349 banking, financial, cryptocurrency and e-wallet applications across 16 countries. Those overlays are invisible to the victim yet capture touch inputs on targeted apps, the report says.
Separately, the malware includes a PIN‑harvesting module that targets 140 financial and cryptocurrency apps and can dynamically update its target list. ToxicPanda also spoofs the Android lock screen to capture device PINs, unlocking patterns and passwords; some samples presented fake system update screens to hide ongoing malicious activity while they operated.
Distribution channels, persistence and device-specific bypasses
Zimperium reports that ToxicPanda 2.0 is being distributed through Amazon AWS‑hosted buckets. The malware’s command set—167 remote commands in the latest version—also contains a persistence-oriented action named “autoBoot.” That command identifies the device manufacturer and opens the corresponding OEM-specific auto-start or power management settings to maintain background activity. According to the researchers, this bypasses battery-consumption protections that would otherwise kill background processes on Xiaomi, OPPO, Vivo, Samsung and Huawei devices.
What this means for technologists, enterprises, and end users
- Technologists and security teams: Zimperium has published a list of indicators of compromise (IoCs) for this ToxicPanda version in a GitHub repository; teams responsible for mobile threat detection should incorporate those IoCs and review network‑level monitoring for devices exhibiting blocked Play Services traffic.
- Affected enterprises and procurement leaders: distribution via Amazon AWS‑hosted buckets highlights the need to include cloud‑hosted distribution vectors in threat-hunting exercises and to evaluate mobile app supply-chain and distribution controls against malicious buckets or object storage.
- End users and mobile administrators: the malware’s use of VPN and Accessibility Service permissions, its invisible overlays, fake lock screens and Wireless ADB abuse mean that unexpected permission requests and prompts to enable developer features merit extra scrutiny; the samples show the attackers pursue both network and local methods to disable or evade platform protections.
ToxicPanda 2.0 assembles a layered approach: network control via VPN permissions, local shell escalation via Wireless ADB, invisible overlays and lock‑screen spoofing, and OEM‑aware persistence. The combination—paired with distribution from cloud buckets and a large, dynamically updateable target list—gives the campaign multiple avenues to evade defenses and capture high-value credentials. Zimperium’s published IoCs and the documented techniques provide concrete artifacts to hunt for; the persistent use of Wireless ADB and the “autoBoot” OEM bypasses underscore how attackers are adapting to and working around platform protections.
Read the original report: https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/




