The ToxicPanda Android malware has been updated with new capabilities that let it block communications with Google Play and Google Play Services, according to mobile security firm Zimperium. The new version, which Zimperium refers to as ToxicPanda 2.0, now requests VPN service permissions to create a local network interface it can control. This network-level control allows the malware to interfere with security checks and actions, including app verifications, updates, Play Protect communication, and other protective measures. The malware uses this access to block Google Play traffic before it extracts and installs its payload, then requests Accessibility Service permissions. Zimperium reports that ToxicPanda 2.0 is being distributed through Amazon AWS-hosted buckets.
The latest iteration of ToxicPanda has significantly expanded its reach, now targeting 349 applications and supporting 167 remote commands. The malware uses phishing overlays for banking, financial, cryptocurrency, and e-wallet applications across 16 countries. It also includes a separate module designed to harvest PINs from 140 financial and cryptocurrency apps, with the ability to dynamically update its target list. According to Zimperium’s researchers, these overlays are invisible to victims, allowing the malware to capture touch inputs on targeted apps without detection.
ToxicPanda also spoofs the Android lock screen to capture device PINs, unlocking patterns, and passwords. Some analyzed samples have been observed using fake system update screens to hide ongoing malicious activity from users. One remote command, called “autoBoot,” identifies the host device manufacturer and launches the corresponding OEM-specific auto-start or power management settings. Zimperium says this technique bypasses battery consumption protections that would otherwise kill background processes on devices made by Xiaomi, OPPO, Vivo, Samsung, and Huawei.
A notable feature in this version is the malware’s automatic abuse of the Android Debug Bridge, or ADB, to gain shell-level access to infected devices. Wireless ADB, which was introduced in Android 11, allows shell commands to be executed over Wi-Fi without a USB connection. Using Accessibility Services permissions, the malware enables Developer Options, activates Wireless Debugging, extracts the six-digit ADB pairing code and port, and connects to the device’s local ADB service. Once it obtains shell user permissions, the malware executes high-privilege commands directly through the ADB daemon, bypassing standard Android runtime consent prompts to grant itself broad permissions and enforce persistence.
Zimperium notes that wireless ADB abuse is a growing trend among Android malware, with other malicious tools implementing similar mechanisms. The security firm cited recent reporting from Group-IB that found a comparable feature in the latest version of the RedHook malware. Zimperium has published a list of indicators of compromise associated with the latest ToxicPanda version in a GitHub repository. As Android malware continues to adopt increasingly sophisticated techniques, users face growing risks from apps that request VPN and Accessibility permissions.
More cybersecurity news from TechManNews.







