• This Android banking trojan uses a fake VPN prompt to silence Goo

    From TechnologyDaily@1337:1/100 to All on Monday, August 24, 2026 16:30:24
    This Android banking trojan uses a fake VPN prompt to silence Google's defenses

    Date:
    Mon, 24 Aug 2026 15:27:41 +0000

    Description:
    ToxicPanda 2.0 abuses Android VPN permissions to block Google Play Protect before stealing banking PINs. Here is how the malware works and how to stay safe.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Researchers found banking malware requests VPN permissions to block Google Play and Play Protect on infected Android phones ToxicPanda 2.0 bypasses security to install hidden payloads, targeting 349 banking and crypto apps across 16 countries The malware can even seize shell-level control of a device Security researchers have flagged a new twist in Android banking malware: a trojan that turns your phone's own VPN feature against you.

    A report from mobile security firm Zimperium details how ToxicPanda 2.0
    abuses VPN permissions to shut down Google's built-in protections before it strikes. The tactic is effective because it hides in plain sight. Plenty of legitimate apps ask for VPN access, and even the best VPN apps rely on the same underlying permission to route your traffic. ToxicPanda copies that request, but uses the access to cut your phone off from Google Play instead.

    Once Google Play Protect can no longer reach the device, the malware has a clear runway to install its payload and begin harvesting your data. How ToxicPanda uses VPN permissions to blind Google Play ToxicPanda operates as a "dropper," an app that smuggles in a second, hidden program. According to Zimperium researchers, the malware first shows a fake installation screen and prompts the victim to grant VPN permissions. That request looks routine, so many users tap "allow" without a second thought. You may like Fake X-VPN installers found to spread credential-stealing malware here's how to stay safe NordVPN warns of fake Ryanair, Emirates, Qatar Airways websites used to spread malware Hundreds of Android banking and crypto apps hit by dangerous new Rokarolla malware

    Granting it lets ToxicPanda create a local network interface that sits
    between the phone and the internet, giving the malware control over all traffic passing through the device. It immediately uses that control to block communication with Google Play and Google Play Services.

    Cutting off this connection lets the malware interfere with app
    verifications, updates, and Play Protect, the security layer that would normally flag or remove a harmful app. With Google effectively blindfolded, ToxicPanda decrypts a payload hidden in its own files, installs it, and then asks for Accessibility Service permissions to dig deeper. (Image credit: Zimperium) This release is a major escalation from the previous ToxicPanda iteration .

    As Zimperium says, ToxicPanda 2.0 now supports 167 remote commands. It can also overlay fake login screens on 349 banking, e-wallet, and crypto apps across 16 countries, up from just 16 apps previously. A separate module harvests PINs from more than 140 financial apps using invisible overlays that capture your taps.

    The trojan can also spoof your Android lock screen to steal your PIN,
    pattern, or password, and it abuses Android's Wireless Debugging (ADB)
    feature to gain shell-level access and grant itself permissions without prompts. What to read next Hackers caught hijacking this Chinese Windows
    VPN's installers to spread malware Apple and Google are hosting hundreds of dangerous VPN links here is why your device is at risk Iran-linked group caught hiding surveillance tools in fake apps

    ToxicPanda first appeared in 2024, targeting European banks. Other similar malware such as Rokarolla, has also hit hundreds of banking and crypto apps
    in recent months. How to stay safe The strongest defense is to keep the malware off your phone in the first place.

    Only install apps from the official Google Play Store, and avoid sideloading APK files from links, ads, or third-party sites. Be aware that dangerous VPN links have even slipped into official app stores , so treat any surprise VPN prompt with suspicion.

    A legitimate VPN remains a valuable privacy tool, but this campaign is a reminder that the permission itself is powerful, so grant it only to apps you genuinely trust. Today's best VPN deals NordVPN 2 Year 2.59 /mth View +3 months free Surfshark 24 Months 1.79 /mth View Proton VPN 24 Month 2.39 /mth View We check over 250 million products every day for the best prices Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!



    ======================================================================
    Link to news story: https://www.techradar.com/vpn/vpn-privacy-security/this-android-banking-trojan -uses-a-fake-vpn-prompt-to-silence-googles-defenses


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)