type: incident ยท created: 2026-08-24 ยท updated: 2026-08-24 ยท tags: ยท confidence: high ยท severity: medium ยท affected_sectors: ยท au_impact: false
Researchers report that ToxicPanda 2.0, an Android banking trojan, now requests VPN service permissions to create a local network interface through which it blocks communications to Google Play and Play Services before extracting and installing its payload. This defeats store-side scanning and makes the malware harder to remove via normal uninstall flows. The technique follows wireless ADB abuse documented earlier in the campaign and continues the family's escalation of on-device fraud capabilities first flagged the prior week. Story date: 2026-08-23.