Urgent.News

What's breaking now, across thousands of outlets.

Tech

This Android banking trojan uses a fake VPN prompt to silence Google's defenses

ToxicPanda 2.0 abuses Android VPN permissions to block Google Play Protect before stealing banking PINs. Here is how the malware works and how to stay safe.

This Android banking trojan uses a fake VPN prompt to silence Google's defenses

A new Android banking trojan known as ToxicPanda 2.0 has emerged, utilizing a deceptive technique to disable Google Play's security measures before executing its malicious payload. This malware, which can target 349 banking and cryptocurrency applications across 16 countries, exploits VPN permissions to achieve this goal.

During installation, ToxicPanda presents a fake dialog requesting VPN permissions, which appears innocuous due to the prevalence of such requests among legitimate apps. Once granted, the malware establishes a local network interface, intercepting all internet traffic on the device. This allows ToxicPanda to block communication with Google Play and Play Protect, thereby bypassing security checks that would typically flag or remove malicious applications.

Subsequently, ToxicPanda decrypts a concealed payload, installs it, and requests Accessibility Service permissions to delve deeper into the device's system. This grants the malware the ability to create fake login screens, capture PINs or passwords through invisible overlays, and even spoof the Android lock screen to obtain sensitive information. Additionally, the trojan can utilize Android's Wireless Debugging (ADB) feature to gain shell-level control, allowing it to bypass prompts and install additional malicious code.

First identified in 2024, ToxicPanda 2.0 represents a significant evolution from its predecessor, offering 167 remote commands and the capability to target a broader range of banking, e-wallet, and crypto applications. To mitigate the risk of infection, users are advised to exclusively download applications from the official Google Play Store, refrain from installing APK files from unverified sources, and exercise caution when encountering VPN-related prompts, as they may conceal malicious intent.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at techradar.com →

More in Tech

More from Monday 24 August →