ToxicPanda 2.0 Abuses Android VPN Permissions to Blind Google Play Protect
Zimperium documents a major ToxicPanda upgrade that abuses Android VPN permissions to blind Google Play Protect and exploits wireless debugging for shell-level device access.
Zimperium’s zLabs research team has detailed a major upgrade to ToxicPanda, an Android banking trojan the firm says has “primarily targeted Europe” since it emerged in the wild. The new version, ToxicPanda 2.0, adds a fake installation screen that talks victims into granting VPN permissions it then uses to silently block Google Play Protect, and it now abuses Android’s own wireless debugging feature to gain shell-level control of infected phones.
Table Of Content
Zimperium published its findings on August 19, 2026, in a report by researcher Vishnu Pratapagiri. According to The Hacker News, which also covered Zimperium’s report, ToxicPanda is also tracked under the alias TgToxic and has been active since at least July 2022. Fraud detection firm Cleafy previously analyzed earlier versions of the malware; Zimperium’s report notes that several commands Cleafy had flagged as unimplemented are now fully operational in the 2.0 release.
A Fake Installation Screen Blinds Google Play Protect
ToxicPanda 2.0 operates as a dropper. Once installed, it shows victims a fake installation screen built with an Android WebView and asks them to grant VPN service permissions. According to Zimperium’s technical writeup and BleepingComputer’s reporting, the malware uses those permissions to build a local network interface it controls, blocking communication between the device and Google Play and Google Play Services before it decrypts and installs its real payload. That timing lets it disable the security checks, update prompts, and Play Protect scans that would otherwise flag the malicious app, before requesting Android’s Accessibility Service permission to begin the next stage of the attack.
Abusing Android’s Debug Bridge for Shell Access
One of the most notable new capabilities is an automated abuse of Android Debug Bridge (ADB), the command-line interface developers normally use to control a device over USB or Wi-Fi. Using its Accessibility Service permissions, ToxicPanda 2.0 silently taps through a phone’s Developer Options menu to enable Wireless Debugging, extracts the six-digit pairing code Android generates for that connection, and pairs with the device’s own local ADB service. Zimperium says that once the malware has shell-level access this way, it “bypasses standard Android runtime consent prompts to grant itself broad permissions, neutralize OS background restrictions, silently enable critical components, and enforce persistence.”
The malware also displays a fake full-screen “system update” overlay to hide what it is doing in the background, and it can place a transparent overlay on top of the device’s real lock screen to capture the PIN, pattern, or password a victim types to unlock their phone. A separate module built specifically for credential theft targets more than 140 banking and cryptocurrency apps for PIN harvesting, and newly active Device Administrator commands let an attacker overwrite a compromised phone’s lock screen credential outright, according to The Hacker News’ report on Zimperium’s findings. One command BleepingComputer highlighted, named “autoBoot,” fingerprints the device’s manufacturer and then opens that OEM’s own auto-start or power management settings, letting the malware exempt itself from the battery restrictions that Xiaomi, OPPO, Vivo, Samsung, and Huawei use to kill background processes.
Wider Targeting, Cloud-Based Distribution
ToxicPanda 2.0’s phishing overlays now impersonate 349 banking, financial, e-wallet, and cryptocurrency apps across 16 countries, up from just 16 targeted banking apps in the prior version, and its remote command set has grown to 167 instructions. The malware communicates with its command and control server over a persistent WebSocket connection secured with AES encryption in ECB mode, using a key embedded directly in its code. Zimperium also found that ToxicPanda 2.0 samples are now being distributed through Amazon AWS-hosted storage buckets, a shift the firm says shows the operators leaning on legitimate cloud infrastructure to host and deliver their payloads.
Zimperium has published indicators of compromise for the campaign on GitHub. Because the malware’s initial VPN and Accessibility Service permission requests are the point where an infection can still be stopped, security researchers continue to recommend that Android users avoid sideloaded apps, scrutinize any app that asks for VPN or Accessibility Service access without an obvious reason, and keep Google Play Protect enabled and up to date.








No Comment! Be the first one.