This Android banking trojan uses a fake VPN prompt to silence Google's defenses

This Android banking trojan uses a fake VPN prompt to silence Google’s defenses | Daily Reports Online

Share


  • Researchers found banking malware requests VPN permissions to block Google Play and Play Protect on infected Android phones
  • ToxicPanda 2.0 bypasses security to install hidden payloads, targeting 349 banking and crypto apps across 16 countries
  • The malware can even seize shell-level control of a device

Security researchers have flagged a new twist in Android banking malware: a trojan that turns your phone’s own VPN feature against you.


A report from mobile security firm Zimperium details how ToxicPanda 2.0 abuses VPN permissions to shut down Google’s built-in protections before it strikes.


Similar Posts