Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SMB cyber lookout: Android malware abusing VPN permissions

What small and medium-sized businesses should look out for today.

Moderate Sunday 23 August 2026, 17:42 UK time
Today’s look-out: Mobile malware on staff Android devices (VPN permission abuse)

What to look out for today

Reports highlight an Android malware family ("ToxicPanda") evolving to target a large number of apps and using VPN-style permissions in a way that can block Google Play. For SMEs, this is mainly a staff device risk—especially where personal phones are used for work (email, Microsoft 365/Google Workspace, banking, payment apps, password managers, messaging apps).

Why this matters to smaller businesses

  • Business accounts live on phones: email, MFA codes, banking approvals and client data are often accessed from mobiles.
  • One infected phone can bypass “office” controls: it may still access cloud services even if your PCs are well protected.
  • Support burden: mobile clean-up and account resets can disrupt small teams quickly.

Warning signs

  • Google Play Store suddenly won’t open or seems blocked/disabled.
  • A prompt to enable a VPN for a non-obvious reason (e.g., “security”, “speed boost”, “ad blocker”, “company access”) that staff didn’t request.
  • Unexpected new apps installed, or apps requesting unusually broad permissions.
  • Staff reporting unusual pop-ups, device slowdowns, or security tools being turned off.

How attackers may exploit the situation

  • Trick a user into granting VPN permissions so the malware can interfere with normal protections (including access to Google Play) and influence what the user can install/update.
  • Target common business apps at scale, aiming to get access to work email, MFA prompts, or financial/payment workflows.
  • Use remote control capabilities to change behaviour over time, making the compromise harder to spot.

What to do today

  • Send a 2-minute staff note: “Don’t approve VPN permission prompts unless you requested them. If Google Play stops working or an app asks for VPN access, report it.”
  • Check your mobile policy: confirm whether personal Android phones are allowed to access work email/M365/Google Workspace, and what minimum controls you expect.
  • Review MFA and recovery settings: ensure key business accounts have up-to-date recovery emails/phones and that admin accounts have stronger protections.
  • Prepare a response step: if a phone is suspected, remove work accounts, reset passwords, revoke sessions/tokens in your cloud admin console, and get the device assessed.

Ask your IT provider

  • Do we have a managed mobile approach (MDM) for any staff phones that access work email/files?
  • Can we require device compliance for access to M365/Google Workspace (e.g., only allow managed or compliant devices)?
  • How quickly can we revoke mobile sessions and force re-authentication across cloud accounts if a phone is compromised?
  • Do we have a simple mobile incident playbook (who to contact, what to disable, what to reset)?

Patch watch - only one short paragraph, and only if relevant

This is not a single “patch it and move on” item. The practical focus today is mobile hygiene and access controls: keep Android devices and key apps up to date, and prioritise limiting which devices can access business systems.

One action today

Send a same-day staff alert: do not approve unexpected VPN permission prompts on Android; if Google Play stops working or a “security/VPN” app appears, report it immediately.

Related Actions On Cyber resource

Actions On Cyber checklist: Staff mobile device security (BYOD) – quick controls and what to do if a phone is compromised

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.