Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » 8 million Android users have been affected by the SpyLoan malware in Google Play loan apps
Global Security

8 million Android users have been affected by the SpyLoan malware in Google Play loan apps

AdminBy AdminDecember 2, 2024No Comments4 Mins Read
Loan Apps on Google Play
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 2, 2024Ravi LakshmananMobile Security / Financial Fraud

Loan programs in Google Play

According to new findings from McAfee Labs, more than a dozen Android malware discovered in the Google Play Store, which have been downloaded more than 8 million times, contain malware known as SpyLoan.

“These PUP (Potentially Unwanted Programs) apps use social engineering tactics to get users to provide sensitive information and grant additional permissions to mobile apps, which can lead to extortion, harassment, and financial loss,” security researcher Fernando Ruiz said in an analysis published last week.

The newly discovered apps aim to offer quick loans with minimal requirements to attract unsuspecting users in Mexico, Colombia, Senegal, Thailand, Indonesia, Vietnam, Tanzania, Peru and Chile.

15 predatory loan programs are listed below. Five of these apps, which are still available for download from the official app store, are said to have been modified in line with Google Play’s policy.

Cyber ​​security
  • Seguro-Fast, secure loan (com.prestamoseguro.ss)
  • Quick loan – Easy loan (com.voscp.rapido)
  • Get baht easy – fast credit (com.uang.belanja)
  • RupiahKilat-Liquids (com.rupiahkilat.best)
  • Borrow with pleasure – Loans (com.gotoloan.cash)
  • Happy Money – quick loan (com.hm.happy.money)
  • KreditKu-Money Online (com.kreditku.kuindo)
  • Dana Kilat-Small Loans (com.winner.rupiahcl)
  • Cash loan (com.vay.cashloan.cash)
  • RapidFinance (com.restrict.bright.cowboy)
  • ReadyForYou (com.credit.orange.enespeces.mtn.ouest.wave.argent.tresor.payer.pret)
  • Huayna Money – Quick loan (com.huaynamoney.prestamos.creditos.peru.loan.credit)
  • IPréstamos: Rápido Crédito (com.credito.iprestamos.dinero.en.linea.chile)
  • Get Sol-Dinero Rápido (com.consegura.sol.pe)
  • EcoPrêt online loan (com.pret.loan.ligne.personnel)

Some of these apps have been advertised in posts on social media platforms such as Facebook, indicating the various methods used by threat actors to trick them into installing victims.

SpyLoan is a repeat offender dating back to 2020, and an ESET report in December 2023 found another set of 18 programs that tried to deceive users offering them loans at high interest rates while stealthily collecting their personal and financial information.

The ultimate goal of the financial scheme is to collect as much information as possible from the infected devices, which can then be used to extort users, forcing them to pay back the loans at higher interest rates, and in some cases, to delay payments or intimidate them with the stolen money. personal photos.

“Ultimately, instead of providing real financial help, these apps can lead users into a cycle of debt and privacy violations,” Ruiz said.

Despite the differences in targeting, the apps were found to use a common framework to encrypt and output data from the victim’s device to the control server (C2). They also follow a similar user experience and onboarding process to apply for a loan.

Cyber ​​security

Additionally, the apps request a number of intrusive permissions that allow them to collect system information, camera, call logs, contact lists, rough location, and SMS messages. Data collection is justified by the fact that it is necessary to identify users and fight fraud.

Users who sign up for the service are verified with a one-time password (OTP) to ensure they have a phone number from the target region. They are also asked to provide additional proof of identity, bank accounts and employee information, all of which are then filtered to the C2 server in an encrypted format using AES-128.

To reduce the risks associated with such apps, it’s important to check app permissions, carefully review app reviews, and verify the legitimacy of the app developer before downloading them.

“The threat of Android apps like SpyLoan is a global problem that exploits users’ trust and financial desperation,” Ruiz said. “Despite law enforcement actions to seize several groups associated with the operation of SpyLoan applications, new operators and cybercriminals continue to exploit these fraudulent activities.”

“SpyLoan programs operate with similar application-level code and C2 across continents. This suggests that there is a common developer or a common framework that is being marketed to cybercriminals. This modular approach allows these developers to quickly distribute malware tailored to different markets. , exploiting local vulnerabilities while maintaining a consistent pattern to trick users.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.