Skip to content
Breaking
Philippines needs broader growth base to withstand shocks, say economistsPoll: BSP to hike rates by 25 bps anewSingapore banks reach $1.2T as regional market weight doublesASEAN Adopts Ambitious Economic Plan to Make Next Leap, Renews Push for Single MarketCelcomDigi and Maxis inject RM202m shareholder advances into DNBToxicPanda 2.0 malware blocks Google Play traffic via VPN to install payloadsMalaysia’s IJM board urges shareholders to reject Sunway’s $2.8 billion takeover bidFBM KLCI slips below 1,724 as bank shares fall before earningsPetronas dividends to fund just 5-6% of 2026 federal revenueSony Xperia 10 VIII design surfaces ahead of 25 August launchVivo Malaysia to launch V80 Lite 5G with 10,000mAh battery on Sept. 3Vietnam tops ASEAN growth chart at 8.39% in Q2 2026Singapore unveils S$70,000 child support package and 12-day childcare leaveSingapore raises childcare leave, launches S$70,000 child support packagePetronas vows to defend Malaysia’s oil, gas rights amid China map disputePetronas strengthens Malaysia’s global shock resilience, says LiewManchester City edge Bournemouth 2-1 in Premier League curtain-raiserMalaysia adds 80 engineers to front-end IC design roles in H1 2026Do auction buyers inherit sellers' strata arrears?TechCrunch Mobility: The custom chip driving Waymo’s robotaxi ambitionsPhilippines needs broader growth base to withstand shocks, say economistsPoll: BSP to hike rates by 25 bps anewSingapore banks reach $1.2T as regional market weight doublesASEAN Adopts Ambitious Economic Plan to Make Next Leap, Renews Push for Single MarketCelcomDigi and Maxis inject RM202m shareholder advances into DNBToxicPanda 2.0 malware blocks Google Play traffic via VPN to install payloadsMalaysia’s IJM board urges shareholders to reject Sunway’s $2.8 billion takeover bidFBM KLCI slips below 1,724 as bank shares fall before earningsPetronas dividends to fund just 5-6% of 2026 federal revenueSony Xperia 10 VIII design surfaces ahead of 25 August launchVivo Malaysia to launch V80 Lite 5G with 10,000mAh battery on Sept. 3Vietnam tops ASEAN growth chart at 8.39% in Q2 2026Singapore unveils S$70,000 child support package and 12-day childcare leaveSingapore raises childcare leave, launches S$70,000 child support packagePetronas vows to defend Malaysia’s oil, gas rights amid China map disputePetronas strengthens Malaysia’s global shock resilience, says LiewManchester City edge Bournemouth 2-1 in Premier League curtain-raiserMalaysia adds 80 engineers to front-end IC design roles in H1 2026Do auction buyers inherit sellers' strata arrears?TechCrunch Mobility: The custom chip driving Waymo’s robotaxi ambitions
AI Edge

ToxicPanda 2.0 malware blocks Google Play traffic via VPN to install payloads

The ToxicPanda 2.0 Android malware strain now blocks Google Play traffic through VPN permissions to install malicious payloads undetected, mobile security firm Zimperium reported.

Source: BleepingComputer · August 23, 2026 at 5:31 PM · AI-assisted report

Single-source
ToxicPanda 2.0 malware blocks Google Play traffic via VPN to install payloads
Photo: J.Archer / CC BY 3.0

KUALA LUMPUR, 24 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

The ToxicPanda 2.0 Android malware strain now blocks Google Play traffic through VPN permissions to install malicious payloads undetected, mobile security firm Zimperium reported.

Market Impact

The new variant targets 349 applications and supports 167 remote commands, up from earlier builds. After gaining VPN rights, it cuts off Google Play and Play Services communications before dropping its payload. Zimperium said the malware is hosted on Amazon AWS buckets and uses overlays invisible to victims to capture touch inputs on banking, financial, cryptocurrency and e-wallet apps across 16 countries.

Once VPN control is established, ToxicPanda interferes with security checks such as app verifications, updates and Play Protect messages. The malware later requests Accessibility Service permissions to begin harvesting PINs, unlock patterns and passwords. Spoofed lock screens and fake system update pages hide ongoing activity, while a PIN-harvesting module separately targets 140 financial and crypto apps and can update targets dynamically.

A standout feature is automatic abuse of the Android Debug Bridge. Wireless ADB, introduced in Android 11, lets the malware enable Developer Options, turn on Wireless Debugging and extract pairing codes without physical access. Zimperium noted this grants shell-level access that bypasses Android runtime consent prompts and neutralises OS background restrictions on devices from Xiaomi, OPPO, Vivo, Samsung and Huawei.

The malware uses an autoBoot command to launch OEM-specific auto-start settings and maintain persistence despite battery optimisation protections. Zimperium said this technique mirrors recent abuse by other families such as RedHook. The company has published indicators of compromise on GitHub.

Related: Google

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.