ToxicPanda Malware Evolves, Bypassing Security Measures on Android Devices
A new version of the ToxicPanda malware has emerged, equipped with advanced features that allow it to evade security checks and install its payload undetected. The malware, which targets 349 applications across 16 countries, has been distributed through Amazon AWS-hosted buckets, according to mobile security company Zimperium.
ToxicPanda 2.0 requests VPN service permissions, allowing it to control network traffic and block communication with Google Play and its services. This enables the malware to interfere with various security checks, including app verifications, updates, and legitimate disruptions designed to protect users. Once installed, the malware extracts and installs its payload before requesting Accessibility Service permissions.
One of the most concerning features of ToxicPanda 2.0 is its ability to abuse the Android Debug Bridge (ADB) protocol, which provides shell-level access to infected devices. The malware enables Developer Options, activates Wireless Debugging, and connects with the device’s local ADB service, allowing it to execute high-privilege commands directly through the ADB daemon. This bypasses standard Android runtime consent prompts, granting the malware broad permissions and enabling persistence.
The use of VPN permissions is a clever tactic employed by ToxicPanda 2.0 to evade detection. By controlling network traffic, the malware can block communication with security services, making it harder for users to identify and remove the infection. Furthermore, the inclusion of phishing overlays for banking, financial, cryptocurrency, and e-wallet applications adds an additional layer of sophistication to the malware.
The researchers have also identified a PIN-harvesting module that targets 140 financial and cryptocurrency apps, allowing the malware to capture device PINs, unlocking patterns, and passwords. Some analyzed samples even used fake system update screens to hide ongoing malicious activity.
Zimperium’s analysis highlights the growing trend of Android malware abusing ADB protocols to gain shell access. This tactic is not unique to ToxicPanda 2.0, as other malware authors have implemented similar mechanisms in their tools. The publication has made available a list of indicators of compromise (IoCs) associated with the latest version of the malware on GitHub.
As users become increasingly reliant on mobile devices for financial transactions and sensitive data storage, it is essential to take proactive measures against such threats. To protect yourself from malware like ToxicPanda 2.0, consider implementing robust security software that includes features such as VPN protection, real-time threat detection, and anti-malware capabilities. Additionally, be cautious when granting permissions to apps, especially those requesting Accessibility Service or VPN permissions. By staying vigilant and informed about the latest threats, you can significantly reduce your risk of falling victim to malware attacks.
Source: Bleeping Computer — 2026-08-23