ToxicPanda 2.0 uses VPN permissions to block Google Play before the payload
Zimperium said ToxicPanda 2.0 requests VPN permissions to block Google Play before the rest of the malware lands. The family supports 167 remote commands and phishing overlays for 349 banking and crypto apps in 16 countries.

On August 23 BleepingComputer reported Zimperium’s analysis of ToxicPanda 2.0. The malware asks for VPN permissions so it can block Google Play before the payload is installed.
What we know
- Zimperium said ToxicPanda 2.0 uses VPN permissions to block Google Play before the payload.
- The malware supports 167 remote commands and phishing overlays for 349 banking and crypto apps in 16 countries.
- It uses AWS-hosted buckets.
- After Accessibility access it enables Developer Options and Wireless Debugging, then uses ADB pairing for a shell.
- A PIN-stealing module covers 140 apps.
Takeaways
- VPN permission is the step that cuts the device off from Google Play before the rest of the implant.
- The overlay catalog covers 349 banking and crypto apps across 16 countries.
- Persistence includes Accessibility, Wireless Debugging, ADB pairing, and a 140-app PIN module.
Source: BleepingComputer


