ToxicPanda turns your phone's VPN switch against you
A banking trojan for Android now asks for one innocuous-looking permission — VPN access — and uses it to cut your phone off from Google's own security service. Then it starts collecting PINs.
Most people have tapped "allow" on a VPN prompt at some point. It looks harmless. ToxicPanda, an Android malware family tracked by mobile security company Zimperium, has built its newest version around that tap.
Once granted VPN permissions, the malware creates a local network interface — think of it as a tollbooth that every bit of your phone's traffic must pass through. Then it blocks traffic to Google Play and Google Play Services. App verification, updates, Play Protect checks: all of it goes quiet. Only after the gate is shut does ToxicPanda unpack its payload, install it, and ask for Accessibility Service permissions — the setting meant to help people who can't easily see or tap a screen. Zimperium says the new version carries fake login screens for 349 banking, financial, cryptocurrency and e-wallet apps across 16 countries, supports 167 remote commands, and includes a separate PIN-harvesting module aimed at 140 finance and crypto apps, with a target list that can be updated on the fly.
The clever part isn't the theft. It's the order of operations. Antivirus and Play Protect only work if they can talk to the outside world. ToxicPanda cuts the phone line first, robs the house second.
The overlays are invisible to the victim, according to Zimperium. You open your banking app, you see your banking app, you tap your PIN — and a transparent layer sitting on top records the touches. ToxicPanda also fakes the Android lock screen to capture PINs, unlock patterns and passwords, and some samples showed a fake "system update" screen to cover activity happening underneath.
Nothing looks wrong. That's the whole design.
There's a second trick that matters more than it sounds. Using Accessibility permissions, the malware switches on Developer Options, turns on Wireless Debugging, reads the six-digit pairing code and port, and connects to the phone's own debugging service — a tool built for developers to run commands on a device over Wi-Fi instead of a USB cable. From there it grants itself permissions without ever showing you a consent prompt. Zimperium notes this is a growing trend: Group-IB recently reported the same mechanism in the RedHook malware.
There's even a command called autoBoot that checks who made your phone and opens the matching auto-start settings, so the battery-saving features on Xiaomi, OPPO, Vivo, Samsung and Huawei devices don't kill it in the background. Someone sat down and studied five manufacturers' power menus.
Anyone who banks on an Android phone — which, for people in their twenties and thirties, is usually the only way they bank. No branch, no desktop, just the app and a six-digit PIN standing between a paycheck and someone else. It also hits people who keep their first few thousand in crypto on a phone wallet: 349 targeted apps include cryptocurrency and e-wallet apps, and the PIN module covers 140 of them. And it touches everyone who has ever been talked into enabling Accessibility or Developer Options by an app that promised something useful — those two switches are the whole attack chain here.
Two things to watch. First, whether Wireless ADB abuse keeps spreading: Zimperium already points to RedHook using the same mechanism, so the question is how many families adopt it next. Second, whether Google changes how VPN permission or Wireless Debugging can be enabled — right now an app that holds Accessibility can flip Developer Options on by itself. Zimperium has published indicators of compromise on GitHub; if Play Protect starts flagging this specific behaviour rather than the files, that's the signal the defence caught up.
The malware doesn't break Android's security. It uses three features Android shipped on purpose: VPN routing, Accessibility, and wireless debugging. Every one of them was added to help someone. That's the uncomfortable part — there's no bug here to patch, only choices to reconsider.
Sources: Bleeping Computer, 23 August 2026, reporting research by Zimperium; Zimperium indicators of compromise published on GitHub; Group-IB report on RedHook cited by Zimperium.
Written by THE TELL’s AI newsroom. how we work · corrections