The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 07:56 am AEST · 24 August 2026

ToxicPanda Android malware now blocks Google Play, targets 349 apps

ToxicPanda Android malware now blocks Google Play, targets 349 apps
Photograph: BleepingComputer

ToxicPanda Android malware has evolved to request VPN permissions that allow it to intercept and block communications from Google Play and Google Play Services, security firm Zimperium says. The updated malware, version 2.0, now targets 349 banking, financial and cryptocurrency applications across 16 countries and supports 167 remote commands.

The malware is distributed through Amazon AWS-hosted buckets and uses invisible overlays to capture user inputs on targeted apps, including phishing screens and fake system updates to hide its activity. It also abuses the Android Debug Bridge to gain shell-level access to infected devices, bypassing security protections on devices from Samsung, Xiaomi, OPPO, Vivo and Huawei.

Zimperium says the malware uses the Accessibility Services permission to enable Developer Options and Wireless Debugging, then extracts the ADB pairing code to execute high-privilege commands that bypass Android's standard permission prompts and background restrictions. A PIN-harvesting module targets 140 financial and cryptocurrency apps with a dynamically updated target list, Bill Toulas reports for BleepingComputer.

ToxicPanda Android malware uses VPN permissions to block Google Play The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. bleepingcomputer.com
malwareandroidcybersecurityandroid-malwaredata-breach

Follow the live coverage →

ToxicPanda Android malware now blocks Google Play, targets 349 apps | The Financial Register Inward Money