ToxicPanda Android malware uses VPN permissions to block Google Play
BLUF
ToxicPanda malware upgraded capabilities now block Google Play access via VPN abuse to maintain persistence.
NEWS
The updated ToxicPanda trojan abuses VPN permissions to prevent users from downloading security patches via the Google Play Store. Its targeting scope has expanded to 349 applications while adding support for 167 new remote commands to enhance attacker control.
Why I Care
Android users risk financial loss and prolonged vulnerability exposure if infection prevents security updates. This tactic allows threat actors to evade detection and maintain long-term access to compromised devices.
Next Steps
Users should audit installed VPN applications and revoke unnecessary permissions immediately. Mobile security teams must update detection signatures for the new command set within 48 hours.
Source: BleepingComputer ·