ToxicPanda Android malware now blocks Google Play, targets 349 apps

ToxicPanda Android malware has evolved to request VPN permissions that allow it to intercept and block communications from Google Play and Google Play Services, security firm Zimperium says. The updated malware, version 2.0, now targets 349 banking, financial and cryptocurrency applications across 16 countries and supports 167 remote commands.
The malware is distributed through Amazon AWS-hosted buckets and uses invisible overlays to capture user inputs on targeted apps, including phishing screens and fake system updates to hide its activity. It also abuses the Android Debug Bridge to gain shell-level access to infected devices, bypassing security protections on devices from Samsung, Xiaomi, OPPO, Vivo and Huawei.
Zimperium says the malware uses the Accessibility Services permission to enable Developer Options and Wireless Debugging, then extracts the ADB pairing code to execute high-privilege commands that bypass Android's standard permission prompts and background restrictions. A PIN-harvesting module targets 140 financial and cryptocurrency apps with a dynamically updated target list, Bill Toulas reports for BleepingComputer.