ToxicPanda 2.0: Android Banking Malware Uses Fake VPN Prompt to Gain Control
A new iteration of Android banking malware has been discovered, dubbed ToxicPanda 2.0 by researchers at Zimperium. This trojan uses a fake VPN prompt to silence Google's defenses and gain control over infected devices.
ToxicPada 2.0 operates as a 'dropper,' an app that smuggles in a second, hidden program. The malware first shows a fake installation screen and prompts the victim to grant VPN permissions, which looks routine but is actually a ploy to cut off communication with Google Play.
With Google effectively blindfolded, ToxicPanda decrypts a payload hidden in its own files, installs it, and then asks for Accessibility Service permissions to dig deeper. This release is a major escalation from the previous iteration, supporting 167 remote commands and overlaying fake login screens on 349 banking, e-wallet, and crypto apps across 16 countries.
The trojan can also spoof your Android lock screen to steal your PIN, pattern, or password, and it abuses Android's Wireless Debugging (ADB) feature to gain shell-level access and grant itself permissions without prompts. To stay safe, researchers recommend only installing apps from the official Google Play Store and being cautious of surprise VPN prompts.