Android Trojan Asks for VPN Access to Block Google Play, Zimperium Says

The mobile security firm Zimperium published an analysis on Aug. 19 of a new build of ToxicPanda, an Android banking trojan the company says had previously concentrated on Europe. Zimperium says the updated malware carries counterfeit login screens for 349 banking, financial, e-wallet and cryptocurrency apps across 16 countries, against 16 banking apps in the version it had analyzed before.
According to the report, the build carries a set of 167 commands its operators can send to an infected phone, and a mechanism aimed at capturing PINs typed into more than 140 banking and cryptocurrency apps. Zimperium says it also draws imitation screens over the Android lock screen to harvest unlock PINs, patterns and passwords, and displays fake "system update" screens to hide what it is doing.
Two capabilities are new relative to earlier versions, the company says. Before installing its payload, the malware presents a counterfeit setup screen asking the user to grant VPN permission; with that permission it blocks the phone's traffic to Google Play and Google Play Services. It also automates the abuse of Android's Wireless Debugging feature, which developers use to send diagnostic commands to a phone over Wi-Fi, to gain shell-level access on the device.
The malware is not distributed through Google Play. Zimperium says the samples it saw were served from Amazon Web Services storage buckets, a change from earlier campaigns.
An earlier version of ToxicPanda was documented by the security firm Cleafy. Zimperium says several commands Cleafy found unimplemented at the time are now working.
