This Android Banking Trojan Uses a Fake VPN Prompt to Silence Google's Defenses
Zimperium says the trojan now supports 167 remote commands and can fake login screens on 349 financial apps across 16 countries.
5 Articles
5 Articles
Advanced Android Banking Trojan Uses Fake VPN to Disable Play Protect
Android banking trojans continue to evolve with increasingly sophisticated techniques designed to bypass mobile security protections. A recent discovery highlights one such threat that employs a deceptive VPN prompt to disable Google Play Protect, the built-in malware scanning service on Android devices. Security researchers at TechRadar reported on this campaign, which demonstrates how attackers combine social engineering with technical tricks …
This Android banking trojan uses a fake VPN prompt to silence Google's defenses
Researchers found banking malware requests VPN permissions to block Google Play and Play Protect on infected Android phonesToxicPanda 2.0 bypasses security to install hidden payloads, targeting 349 banking and crypto apps across 16 countries The malware can even seize shell-level control of a deviceSecurity researchers have flagged a new twist in Android banking malware: a trojan that turns your phone's own VPN feature against you. A report from…
ToxicPanda 2.0 Blocks Google Play as Android Malware Targets 349 Financial Apps
ToxicPanda 2.0 now targets 349 financial apps across 16 countries while abusing VPN, Accessibility and Android debugging features for deeper control. This article has been indexed from eSecurity Planet Read the original article: ToxicPanda 2.0 Blocks Google Play as Android Malware Targets 349 Financial Apps The post ToxicPanda 2.0 Blocks Google Play as Android Malware Targets 349 Financial Apps appeared first on IT Security News.
ToxicPanda 2.0 Blocks Google Play
ToxicPanda 2.0 is giving attackers deeper remote control over infected Android phones, including a new way to keep Google Play out of the way. Security researchers at Zimperium’s zLabs have uncovered a new version of the ToxicPanda Android banking Trojan with a far wider reach and a much larger arsenal of commands. The malware now supports 167 remote commands and can target 349 banking, financial, e-wallet and cryptocurrency applications across …
The 'malware' ToxicPanda has evolved to a new 2.0 version that incorporates 167 remote commands, as well as expanding its attack capabilities to Android devices, targeting 349 banking applications in 16 countries, with options to steal PIN keys and credentials via fake screens and block Google security services.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium







