← Terug naar overzicht

ToxicPanda is an Android malware that has evolved with new malicious functionality, now targeting 349 applications and supporting 167 remote commands. The malware abuses VPN permissions to intercept and block access to Google Play, likely to prevent detection or removal of itself. This expansion in targeting and command support indicates active development and a growing threat surface. The malware appears designed for financial fraud or data theft by intercepting app traffic. Its use of VPN permissions as a defensive evasion technique represents a notable evolution in Android malware tradecraft. The growing list of targeted applications suggests threat actors are broadening their victim pool across multiple sectors and geographies.

Technical details

ToxicPanda 2.0 is an evolved Android banking malware with the following key capabilities: (1) VPN Service Abuse: Requests VPN service permissions to create a local network interface, enabling it to intercept and block network traffic to Google Play and Google Play Services, preventing app verifications, updates, and Play Protect communications. (2) Payload Delivery: After obtaining VPN permissions and blocking Google Play, it extracts and installs its payload, then requests Accessibility Service permissions. (3) Wireless ADB Abuse: Uses Accessibility Services to enable Developer Options, activate Wireless Debugging (Android 11+), extract the six-digit ADB pairing code and port, and connect to the device's local ADB service to gain shell-level access. Once shell access is obtained, it executes high-privilege commands through the ADB daemon, bypasses Android runtime consent prompts, grants itself broad permissions, neutralizes OS background restrictions, and silently enables critical components. (4) Phishing Overlays: Supports invisible phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications targeting 16 countries; overlays capture touch inputs on targeted apps without victim awareness. (5) PIN Harvesting: Includes a separate PIN-harvesting module targeting 140 financial and cryptocurrency apps with dynamically updatable target lists; also spoofs the Android lock screen to capture device PINs, unlock patterns, and passwords. (6) Fake Update Screens: Uses fake system update screens to conceal ongoing malicious activity. (7) Persistence via 'autoBoot': Identifies the host device manufacturer and launches OEM-specific auto-start or power management settings to maintain persistence, bypassing battery consumption protections on Xiaomi, OPPO, Vivo, Samsung, and Huawei devices. (8) Remote Commands: Supports 167 remote commands. (9) Distribution: Distributed via Amazon AWS-hosted S3 buckets.

Mitigation steps

1. Avoid sideloading APKs from untrusted sources, including third-party app stores or unknown download links. 2. Do not grant VPN service permissions or Accessibility Service permissions to unrecognized or suspicious applications. 3. Keep Google Play Protect enabled and ensure it is not being blocked by any installed apps. 4. Monitor for suspicious use of VPN service permissions and Accessibility Services on Android devices. 5. Disable Developer Options and Wireless Debugging on devices where they are not required. 6. Use a mobile threat defense (MTD) solution such as Zimperium to detect ToxicPanda and similar threats. 7. Review and monitor the Indicators of Compromise (IoCs) published by Zimperium at https://github.com/Zimperium/IOC/tree/master/2026-08-ToxicPanda. 8. Investigate any connections to Amazon AWS-hosted buckets that may be serving malicious APKs. 9. For enterprise environments, enforce mobile device management (MDM) policies that restrict sideloading and monitor for unauthorized permission grants. 10. Be alert to fake system update screens on Android devices as a sign of potential infection.

Affected products

  • Android (Android 11 and above for Wireless ADB feature)
  • Banking
  • Financial and cryptocurrency apps (140 targeted by PIN-harvesting module)
  • Google Play / Google Play Services (blocked by malware)
  • Huawei devices
  • OPPO devices
  • Samsung devices
  • Vivo devices
  • Xiaomi devices
  • and e-wallet applications (349 targeted apps)
  • cryptocurrency
  • financial

IOC's

Distribution via Amazon AWS-hosted buckets, IOC list published by Zimperium: https://github.com/Zimperium/IOC/tree/master/2026-08-ToxicPanda, Command list: https://github.com/Zimperium/IOC/blob/master/2026-08-ToxicPanda/commands.md

Categories

  • Identity & Access
  • Mobile & IoT
  • Ransomware & Malware