Home » Technology » Beware of ToxicPanda: This Android Trojan blocks Google Play

Beware of ToxicPanda: This Android Trojan blocks Google Play

A new version of the Android Trojan ToxicPanda threatens users of financial and crypto applications worldwide. The malware undermines security functions and takes almost complete control of the infected smartphones.

Dangerous Android malware in circulation

The ToxicPanda 2.0 banking Trojan targets 349 financial and crypto applications and attempts to steal digital assets. It is mainly spread via fake apps outside of official stores. Users unknowingly download manipulated browser or dating apps and thus install the Trojan. The Federal Office for Information Security (BSI) classifies the threat as high. A Trojan does not spread independently but requires active installation by the user. Once activated, the program intercepts codes for two-factor authentication.

Malware blocks Google Play

Like the security company Cimperium reported, the new variant uses 167 different remote commands. A central element of the attack strategy is blocking the Google Play service. By controlling at the network level, the malware prevents important app checks in the background, thereby protecting itself from detection by the operating system’s built-in security mechanisms. Security researchers are particularly critical of the misuse of the Android Debug Bridge (ADB). The troubleshooting interface, which is actually intended for developers, is activated by the malware to enable wireless debugging functions and read the necessary pairing code.

Abuse and protection measureThis gives attackers extensive administrative rights, allows them to execute commands with high privileges and permanently manipulate security settings. In order to remain active on the devices, the program specifically bypasses the energy saving functions of various manufacturers such as Samsung or Xiaomi. The perpetrators use invisible overlays on the screen to record every touch. Sometimes they display fake system updates to disguise ongoing attacks.

The lock screen is also imitated to access access data. Although open operating systems allow software to be installed from any source, this poses significant risks to data security. Users should not carry out installations from unknown sources and should critically question requested permissions for virtual private network (VPN) traffic. It is also advisable to always install system updates promptly.

Leave a Reply