ShellCodeX Intelligence Brief
HIGH
Mobile Security
ToxicPanda Android malware uses VPN permissions to hinder Google Play
Source headline: ToxicPanda Android malware uses VPN permissions to block Google Play
Threat level
High
Signal strength
65/100
Source confidence
1 source
Published
1 hour ago
Intelligence Summary
ToxicPanda Android malware has added new malicious functionality. The malware now targets 349 applications. It also supports 167 remote commands. The campaign leverages VPN permissions to block access to Google Play. Users should review Android device security and remove any ToxicPanda infections, especially on affected devices.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.
Topics
Original reporting
BleepingComputer
ToxicPanda Android malware uses VPN permissions to block Google Play
Open original source