CybersecurityAugust 23, 2026· via BleepingComputer

ToxicPanda malware abuses VPN permissions to block Google Play

ToxicPanda malware abuses VPN permissions to block Google Play

Image : BleepingComputer

A new variant of the ToxicPanda Android malware has quietly slipped into the wild, weaponizing VPN permissions to block users from accessing Google Play and expanding its reach to 349 apps—while also unlocking 167 remote commands for attackers.

A stealthy upgrade in mobile malware

First uncovered several years ago, ToxicPanda has evolved beyond its original spyware roots. The latest version leverages the VPN permission—typically reserved for legitimate privacy tools—to intercept and restrict network traffic. Instead of encrypting traffic like a real VPN service, it now blocks requests to Google Play, preventing users from installing security updates or legitimate apps. Researchers note that once installed, the malware also targets a broad list of apps across categories such as banking, social media, and messaging.

How it spreads and what it does

The malware is distributed through trojanized versions of popular apps, often hosted on third-party stores or disguised as utility tools. Once launched, it requests VPN permissions under the guise of “enhancing security.” With that access, ToxicPanda can silently block access to Google Play by manipulating network filters. It also responds to 167 remote commands, enabling attackers to steal data, intercept messages, or even overlay fake login screens on targeted apps.

Why it matters

This evolution signals a troubling trend: malware authors are increasingly abusing legitimate Android permissions to deliver more invasive and harder-to-detect threats. By blocking Google Play, ToxicPanda not only prevents users from updating their devices but also neutralizes one of the primary defenses against such attacks. It underscores the need for stricter app store vetting, user vigilance regarding permission requests, and timely OS updates—especially for users in regions where third-party app stores are common.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home