Skip to content
See the World Through Science

Android Trojan Asks for VPN Access to Block Google Play, Zimperium Says

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A statue of the Android robot mascot holding an Oreo biscuit, standing by a window above a city skyline at dusk
A statue of the Android mascot in the 'Oreo' costume that marked Android 8.0, by a window above a city skyline. The trojan described in the report runs on Android phones and is installed from outside Google Play."Android Oreo's Mascot" by David Kernan, via wikimedia, CC-BY-4.0 · CC-BY-4.0

The mobile security firm Zimperium published an analysis on Aug. 19 of a new build of ToxicPanda, an Android banking trojan the company says had previously concentrated on Europe. Zimperium says the updated malware carries counterfeit login screens for 349 banking, financial, e-wallet and cryptocurrency apps across 16 countries, against 16 banking apps in the version it had analyzed before.

According to the report, the build carries a set of 167 commands its operators can send to an infected phone, and a mechanism aimed at capturing PINs typed into more than 140 banking and cryptocurrency apps. Zimperium says it also draws imitation screens over the Android lock screen to harvest unlock PINs, patterns and passwords, and displays fake "system update" screens to hide what it is doing.

Two capabilities are new relative to earlier versions, the company says. Before installing its payload, the malware presents a counterfeit setup screen asking the user to grant VPN permission; with that permission it blocks the phone's traffic to Google Play and Google Play Services. It also automates the abuse of Android's Wireless Debugging feature, which developers use to send diagnostic commands to a phone over Wi-Fi, to gain shell-level access on the device.

The malware is not distributed through Google Play. Zimperium says the samples it saw were served from Amazon Web Services storage buckets, a change from earlier campaigns.

An earlier version of ToxicPanda was documented by the security firm Cleafy. Zimperium says several commands Cleafy found unimplemented at the time are now working.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Android Trojan Asks for VPN Access to Block Google Play, Zimperium Says

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.