HomeInvestigationsAndroid Gooligan Hacked 1 Million Google Accounts Check Yours

Android Gooligan Hacked 1 Million Google Accounts Check Yours

Android Gooligan: If you have an Android smartphone, you might want to check if it has been compromised. A new Android malware that has already compromised over 1 million Google accounts and infects around 13,000 devices every day.

They called it Gooligan and it can root Android devices to steal stored email addresses and authentication tokens.gooligan

With this information, attackers are able to compromise your Google account and gain access to sensitive information from Google apps such as Gmail, Google Photos, Google Docs, Google Play, Google Drive, and G Suite.

Researchers found traces of Gooligan code in dozens of legitimate Android search apps available in third-party app stores. If you use one of these apps on your Android device, the malware begins sending the information contained within it to a hacker's command-and-control (C&C) server.

“Gooligan then downloads a rootkit from the C&C server that can exploit multiple vulnerabilities in Android 4 and 5 including the well-known VROOT (CVE-2013-6282) and Towelroot (CVE-2014-3153),” the researchers said.

“If root is successful, the attacker has full control of the device and can execute privileged commands remotely.”

According to security researchers at CheckPoint, who uncovered the malware, any user of an older version of the Android operating system (4.x Android Jelly Bean, KitKat and 5.x, Lollipop) is at risk. These operating systems are present on 74% of Android devices in use today.

"These exploits can hit many devices today because the security patches that fix them may not be available for some versions of Android, or have not been installed by the user," the researchers added.

Once it compromises any Android device, Gooligan begins generating revenue for the hackers by purchasing apps from the Google Play Store and writing reviews on behalf of the phone owner. The malware also installs adware to generate additional revenue for the hackers.

Google's official position on the matter, as we received it from the company:

“We appreciate the contribution of Check Point , with whom we have collaborated to understand and address such issues. It is worth emphasizing that as part of our ongoing effort to protect users from the Ghost Push, we have taken numerous measures and are taking protective measures to improve security across the Android. Specifically, our actions include: revoking the tokens of users whose devices have been infected, providing clear instructions for them to safely log back in, disabling the apps associated with this issue from infected devices, continuously developing verification apps and continuous improvements to SafetyNet to protect users from these apps in the future, and working with Internet Service Providers (ISPs)to eliminate this malware completely.”

Adrian Ludwig, Director Android Security

How to check if your Google account has been hacked?

Check Point has released an online tool that will help you check if your Android device has been infected with the Gooligan malware. Simply open the “Gooligan Checker” and enter your (Google) email address to find out if you have been hacked.

If you find yourself infected, Adrian Ludwig, director of Android security at Google, recommends performing a clean install of the operating system on your device.

It should be mentioned that with this specific tool, Check Point will collect as many emails as it has never collected since it began operating..

https://gooligan.checkpoint.com/

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS