Skip to main content
See every side of every news story
Published loading...Updated

This Android Banking Trojan Uses a Fake VPN Prompt to Silence Google's Defenses

Zimperium says the trojan now supports 167 remote commands and can fake login screens on 349 financial apps across 16 countries.

Summary by Tech Radar
Researchers found banking malware requests VPN permissions to block Google Play and Play Protect on infected Android phonesToxicPanda 2.0 bypasses security to install hidden payloads, targeting 349 banking and crypto apps across 16 countries The malware can even seize shell-level control of a deviceSecurity researchers have flagged a new twist in Android banking malware: a trojan that turns your phone's own VPN feature against you. A report from…

5 Articles

The 'malware' ToxicPanda has evolved to a new 2.0 version that incorporates 167 remote commands, as well as expanding its attack capabilities to Android devices, targeting 349 banking applications in 16 countries, with options to steal PIN keys and credentials via fake screens and block Google security services.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

diarioestrategia.cl broke the news on Monday, August 24, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal