Tech

Malware That Blinds Google’s Protection Before It Steals: The Signs That Give It Away

Instead of evading the scan, it cuts the connection to it. How it works, the five markers on your device, and two permissions never to grant.

A close macro view of an electronic circuit board

The new trick in a piece of malware targeting Android phones is worth understanding, because its logic applies well beyond it: instead of trying to evade Google’s protection, it cuts the connection to it.

On 19 August Zimperium published an analysis of an updated version of a banking trojan known as Toxic Panda. What is new is that it requests the “VPN service” permission, then creates a local network interface which it uses to block the connection to the Google Play Store and to Google Play Services.

Blocking that connection means disabling the scanning Google performs on apps. Blind the guard first, then walk in.

What it does next

According to the same analysis, it shows phishing overlays on top of banking apps, runs a module dedicated to stealing the PIN, displays a fake lock screen, and executes system-level commands whenever it has the permission.

The company says the new version carries fake screens for 349 banking, financial, e-wallet and cryptocurrency apps, up from sixteen in the first version, and that more than a hundred and forty apps are specifically targeted for PIN theft. It also has persistence methods tailored to Xiaomi, Oppo, Vivo, Samsung and Huawei devices.

The signs that give it away

This is the practical part, because the same signs recur in other malware:

  • An “install” screen appearing inside a web view that does not look like a system screen.
  • A full-screen “system update” window that did not come from Settings.
  • A lock screen that looks familiar but is not your device’s lock screen.
  • A request for the “Accessibility” permission.
  • A request for the “Device admin” permission.

Three rules are enough

Do not grant “Accessibility” or “Device admin” to an app that is not genuinely an assistive tool. Those two permissions give an app the ability to read what is on your screen and tap on your behalf. A shopping app does not need them, nor does a game, nor a delivery app.

A VPN permission request from an app that is not a VPN is a stop sign. Not a warning to click past, but a reason to uninstall.

Banking apps are installed from the official store only. Not from a link in a message, and not from a file sent over a chat app.

How to review your device now

Open Settings, then “Accessibility”, and look at which apps are enabled there. Then Settings, then “Security”, then “Device admin apps”. Any name you do not recognise, or whose presence in those two lists you cannot explain, deserves to be switched off.

What the analysis did not say

Two points, because ignoring them turns a report into scaremongering:

The first is that Zimperium said the targeting covers sixteen countries, but did not publish which countries. So there is nothing establishing that Kuwait or the Gulf states are among them, and nothing ruling it out.

The second is that the analysis does not say how the malware reaches the phone in the first place; it describes what happens after it arrives. Anyone telling you it spreads through a particular message or a particular store is adding that themselves.

Source: the Zimperium Labs analysis published on 19 August 2026, and specialist information security coverage on 22 and 23 August.

Photo: an electronic circuit board close up. By Phiarc, CC BY-SA 4.0 via Wikimedia Commons.

Kuwait One, once a week.

The most useful stories we published this week, in your inbox.

No spam. Unsubscribe anytime.

Leave a comment

Your email will not be published. Comments are reviewed before they appear.