This Android banking trojan uses a fake VPN prompt to silence Google's defenses

https://cdn.mos.cms.futurecdn.net/tEhgdM2MKoCYRwV4Ch3awa-2048-80.jpg
  • Researchers found banking malware requests VPN permissions to block Google Play and Play Protect on infected Android phones
  • ToxicPanda 2.0 bypasses security to install hidden payloads, targeting 349 banking and crypto apps across 16 countries
  • The malware can even seize shell-level control of a device

Security researchers have flagged a new twist in Android banking malware: a trojan that turns your phone's own VPN feature against you.

A report from mobile security firm Zimperium details how ToxicPanda 2.0 abuses VPN permissions to shut down Google's built-in protections before it strikes.

The tactic is effective because it hides in plain sight. Plenty of legitimate apps ask for VPN access, and even the best VPN apps rely on the same underlying permission to route your traffic. ToxicPanda copies that request, but uses the access to cut your phone off from Google Play instead.

Once Google Play Protect can no longer reach the...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more