Daily Security Intel

Archives
Log in
Subscribe
August 24, 2026

[SecurityIntel] 24 Aug | ToxicPanda Android Malware Abuses VPN Permissions

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, August 24, 2026

INTEL CONFIDENCE  82%

THREAT LEVEL

HIGH

THREAT OF THE DAY

ToxicPanda Android Malware Abuses VPN Permissions

HIGH

5

C2 IPs

18

OTX IOCs

2

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by the evolution of the ToxicPanda Android banking trojan, which has expanded its capabilities to target 349 applications. The malware now abuses Android VPN permissions to block Google Play Protect and system updates while executing remote commands. Additionally, SANS ISC provides telemetry on daily threat activities, emphasizing the need for robust perimeter monitoring.

■ CRITICAL STORIES

HIGH#1

ToxicPanda Android Malware Abuses VPN Permissions to Block Google Play

The malware has evolved to target 349 applications with 167 remote commands, leveraging Android's VpnService to intercept traffic and disable Google Play Protect, facilitating undetected on-device fraud.

INFO#2

ISC Stormcast Daily Threat Briefing

Daily analysis of global threat telemetry highlights ongoing scanning and opportunistic exploitation patterns, underscoring the importance of continuous log analysis and firewall rule updates.

■ CVEs IDENTIFIED

[CVE-TBD]

Google Android OS — Defense evasion and security tool blocking via VpnService permission abuse

High

[CVE-TBD]

Google Play Protect — Local bypass and update prevention by malicious VPN configurations

Medium

■ THREAT ACTORS

ToxicPanda Operators

Cybercrime Group

Distributing updated Android banking malware targeting financial applications and abusing system-level permissions

■ ATT&CK TTPs

T1562.001
Impair Defenses: Disable or Modify Tools | ToxicPanda uses VPN permissions to block Google Play Protect and system updates
T1543.003
Abuse Elevation Control Mechanism: Access Services | ToxicPanda abuses Android Accessibility Services to perform actions on behalf of the user
T1071.001
Application Layer Protocol: Web Protocols | ToxicPanda communicates with command-and-control servers to receive 167 remote commands
T1418
Input Capture | ToxicPanda targets 349 applications to harvest sensitive user inputs and credentials

■ PATCH PRIORITY

[P2 PATCH NOW]≤72h

Google Android OS — Prevent untrusted applications from abusing VpnService and Accessibility APIs to disable system security controls — BleepingComputer

[P3 PATCH NOW]≤1 week

Google Play Protect — Implement tamper-resistance mechanisms to prevent local malware from blocking updates — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Implement Mobile Device Management (MDM) policies on Android OS to restrict sideloading of applications and block unauthorized use of the VpnService API.
2[P2] Deploy Mobile Threat Defense (MTD) solutions to detect ToxicPanda indicators, specifically unauthorized attempts to disable Google Play Protect.
3[P2] Educate enterprise users against granting Accessibility and VPN permissions to untrusted or non-managed applications on Android OS.
4[P3] Monitor network gateways for unauthorized VPN connections or traffic destined for known ToxicPanda command-and-control nodes.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 23 Aug | Android Car Head Units Hit By Supply-Chain Botnet
Powered by Buttondown, the easiest way to start and grow your newsletter.