This morning we published about Android Gooligan. If you have an Android smartphone, it would be a good idea to check if it has been compromised. A new Android malware that has already compromised over 1 million Google accounts and infects about 13,000 devices every day.

They called it Gooligan and it can root Android devices to steal stored email addresses and authentication tokens.
You can read more in our first post.
Google reportedly issued an official statement on the matter, which we publish below as we received it:
“Following your publication on the issue that has arisen regarding the malicious Gooligan app, we are sending you Google's official position with the request that you also include it in your publication.
“We appreciate the contribution of Check Point , with whom we have collaborated to understand and address such issues. It is worth emphasizing that as part of our ongoing effort to protect users from the Ghost Push, we have taken numerous measures and are taking protective measures to improve security across the Android.
Specifically, our actions include: revoking the tokens of users whose devices have been infected, providing clear instructions to safely sign in again, disabling the apps associated with this issue from infected devices, continuously developing verification apps and making ongoing improvements to SafetyNet to protect users from these apps in the future, and working with internet service providers (ISPs)to eliminate this malware completely.”
Adrian Ludwig, Director Android Security
