SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, August 24, 2026 INTEL CONFIDENCE 82% | THREAT LEVEL HIGH |
|
THREAT OF THE DAY ToxicPanda Android Malware Abuses VPN Permissions | HIGH |
|
5 C2 IPs | 18 OTX IOCs | 2 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by the evolution of the ToxicPanda Android banking trojan, which has expanded its capabilities to target 349 applications. The malware now abuses Android VPN permissions to block Google Play Protect and system updates while executing remote commands. Additionally, SANS ISC provides telemetry on daily threat activities, emphasizing the need for robust perimeter monitoring. |
|
■ CRITICAL STORIES ToxicPanda Android Malware Abuses VPN Permissions to Block Google Play The malware has evolved to target 349 applications with 167 remote commands, leveraging Android's VpnService to intercept traffic and disable Google Play Protect, facilitating undetected on-device fraud. |
ISC Stormcast Daily Threat Briefing Daily analysis of global threat telemetry highlights ongoing scanning and opportunistic exploitation patterns, underscoring the importance of continuous log analysis and firewall rule updates. |
|
■ CVEs IDENTIFIED [CVE-TBD] Google Android OS — Defense evasion and security tool blocking via VpnService permission abuse |
[CVE-TBD] Google Play Protect — Local bypass and update prevention by malicious VPN configurations |
|
■ THREAT ACTORS ToxicPanda Operators | Cybercrime Group |
Distributing updated Android banking malware targeting financial applications and abusing system-level permissions |
|
|
|
■ ATT&CK TTPs | T1562.001 | | Impair Defenses: Disable or Modify Tools | ToxicPanda uses VPN permissions to block Google Play Protect and system updates |
| T1543.003 | | Abuse Elevation Control Mechanism: Access Services | ToxicPanda abuses Android Accessibility Services to perform actions on behalf of the user |
| T1071.001 | | Application Layer Protocol: Web Protocols | ToxicPanda communicates with command-and-control servers to receive 167 remote commands |
| T1418 | | Input Capture | ToxicPanda targets 349 applications to harvest sensitive user inputs and credentials |
|
■ PATCH PRIORITY Google Android OS — Prevent untrusted applications from abusing VpnService and Accessibility APIs to disable system security controls — BleepingComputer |
Google Play Protect — Implement tamper-resistance mechanisms to prevent local malware from blocking updates — BleepingComputer |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Implement Mobile Device Management (MDM) policies on Android OS to restrict sideloading of applications and block unauthorized use of the VpnService API. |
| 2 | [P2] Deploy Mobile Threat Defense (MTD) solutions to detect ToxicPanda indicators, specifically unauthorized attempts to disable Google Play Protect. |
| 3 | [P2] Educate enterprise users against granting Accessibility and VPN permissions to untrusted or non-managed applications on Android OS. |
| 4 | [P3] Monitor network gateways for unauthorized VPN connections or traffic destined for known ToxicPanda command-and-control nodes. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |