LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials
malware

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]

zeroday.news ·

The ToxicPanda Android malware has undergone significant evolution, expanding its targeting to 349 applications across 16 countries and supporting 167 remote commands. A key new feature is its use of VPN service permissions to establish a local network interface, allowing it to control network traffic. This capability, observed in ToxicPanda 2.0, enables the malware to block communications from Google Play and Google Play Services, thereby interfering with security checks, app verifications, updates, and Play Protect interactions.

According to mobile security researchers, ToxicPanda 2.0 is being distributed via Amazon AWS-hosted buckets. After obtaining VPN service permissions, the malware first blocks Google Play communications before extracting and installing its payload, then requests Accessibility Service permissions.

A notable development in the latest ToxicPanda version is its automated abuse of the Android Debug Bridge (ADB). Utilizing Accessibility Services permission, the malware enables Developer Options, activates Wireless Debugging (introduced in Android 11), extracts the six-digit ADB pairing code and port, and connects to the device's local ADB service. This grants the malware shell-level access to infected devices. With shell user permissions, the malware can execute high-privilege commands directly through the ADB daemon, bypassing standard Android runtime consent prompts to grant itself broad permissions, neutralize OS background restrictions, silently enable critical components, and enforce persistence. This method of abusing wireless ADB has been observed in other Android malware, such as the RedHook malware.

The malware now includes functions to automate ADB, enabling shell-level access. It also supports phishing overlays for 349 banking, financial, cryptocurrency, and e-wallet applications. A separate PIN-harvesting module targets 140 financial and cryptocurrency apps, with the ability to dynamically update its target list. The app overlays are designed to be invisible to victims, allowing the malware to capture touch inputs. ToxicPanda also spoofs the Android lock screen to capture device PINs, unlocking patterns, and passwords. Some analyzed samples also employed fake system update screens to conceal ongoing malicious activities.

One of the remote commands, "autoBoot," identifies the host device manufacturer and launches OEM-specific auto-start or power management settings. This allows the malware to maintain persistence by bypassing battery consumption protections that terminate background processes on devices from manufacturers such as Xiaomi, OPPO, Vivo, Samsung, and Huawei.

Indicators of compromise (IoCs) associated with the latest ToxicPanda version have been published in a public GitHub repository.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
iran

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Hackers linked to Iran have successfully disabled a small UK power plant for four days, marking the first confirmed attack of its kind against the nation's energy infrastructure. The incident occurred concurrently with cyberattacks targeting water facilities across 12 US states. While the UK power plant's outage did not impact the national grid, the attack served as a demonstration of capability, with intentions likely focused on showcasing access rather than causing widespread disruption.

ransomware

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assume

aihigh

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Researchers at Adversa AI have developed a novel attack called Cryptographic Context Injection, which bypasses AI safety filters by embedding malicious instructions within AES-encrypted payloads. This technique tricks AI models like xAI's Grok and Google's Gemini into decrypting and executing these hidden commands. In the case of Grok, the attack can lead to zero-click theft of user chat histories and personal data by disguising the malicious payload as a webpage summary request.

breach

Welcoming the Sri Lankan Government to Have I Been Pwned

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]