ToxicPanda Malware Evolves, Targeting 349 Apps with Remote Commands
The ToxicPanda Android malware has evolved to become even more malicious, targeting 349 applications and adding support for 167 remote commands. This new version of the malware requests VPN service permissions to create a local interface that allows it to control network traffic passing through it.
With this feature, ToxicPanda 2.0 can block communication from Google Play and Google Play Services, interfering with various security checks and actions such as app verifications, updates, and legitimate disruptions designed to protect users.
The malware also includes functions to automate the Android Wireless Debugging Bridge (ADB), enabling shell-level access to infected devices. This allows the attackers to bypass battery consumption protections on certain devices and maintain persistence.