{
  "id": 3054730,
  "title": "This Android banking trojan uses a fake VPN prompt to silence Google's defenses",
  "url": "https://urgent.news/2026/08/24/this-android-banking-trojan-uses-a-fake-vpn-prompt-to-silence-googles",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-24T15:27:41.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/vpn/vpn-privacy-security/this-android-banking-trojan-uses-a-fake-vpn-prompt-to-silence-googles-defenses"
  },
  "original_language": "en",
  "account": "A new Android banking trojan known as ToxicPanda 2.0 has emerged, utilizing a deceptive technique to disable Google Play's security measures before executing its malicious payload. This malware, which can target 349 banking and cryptocurrency applications across 16 countries, exploits VPN permissions to achieve this goal.\n\nDuring installation, ToxicPanda presents a fake dialog requesting VPN permissions, which appears innocuous due to the prevalence of such requests among legitimate apps. Once granted, the malware establishes a local network interface, intercepting all internet traffic on the device. This allows ToxicPanda to block communication with Google Play and Play Protect, thereby bypassing security checks that would typically flag or remove malicious applications.\n\nSubsequently, ToxicPanda decrypts a concealed payload, installs it, and requests Accessibility Service permissions to delve deeper into the device's system. This grants the malware the ability to create fake login screens, capture PINs or passwords through invisible overlays, and even spoof the Android lock screen to obtain sensitive information. Additionally, the trojan can utilize Android's Wireless Debugging (ADB) feature to gain shell-level control, allowing it to bypass prompts and install additional malicious code.\n\nFirst identified in 2024, ToxicPanda 2.0 represents a significant evolution from its predecessor, offering 167 remote commands and the capability to target a broader range of banking, e-wallet, and crypto applications. To mitigate the risk of infection, users are advised to exclusively download applications from the official Google Play Store, refrain from installing APK files from unverified sources, and exercise caution when encountering VPN-related prompts, as they may conceal malicious intent.",
  "summary": "ToxicPanda 2.0 abuses Android VPN permissions to block Google Play Protect before stealing banking PINs. Here is how the malware works and how to stay safe.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "9to5Google",
        "title": "Deals: TCL Android tablets from $150, Chipolo Google Find Hub wallet CARD $33, LG C6 OLED $1,000 off + $50 credit, more",
        "url": "https://urgent.news/2026/08/24/deals-tcl-android-tablets-from-150-chipolo-google-find-hub-wallet",
        "published": "2026-08-24T15:31:42.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}