Cybersecurity researchers discovered malicious Android by Spyloan, which were removed.

“Essentially, these services are designed to defraud users by offering them high-interest loans. In doing so, they collect personal and financial information from their victims in order to blackmail them and extort their money,” ESET.
Read also: AutoSpill: Steals credentials from Android password managers
The Slovakian cybersecurity is tracking these apps under the name SpyLoan, noting that they are designed to attack potential borrowers in Southeast Asia, Africa, and Latin America.
The list of applications that have now been removed by Google is as follows:
- AA Kredit: instant loan app (com.aa.kredit.android)
- Amor Cash: Préstamos Sin Buró (com.amorcash.credito.prestamo)
- Oro Préstamo – Efectivo rápido (com.app.lo.go)
- Cashwow (com.cashwawow.cow.eg)
- CrediBus Préstamos de crédito (com.dinero.profin.prestamo.credito.credit.credibus.loan.efectivo.cash)
- loan with confidence – flashloan (com.flashloan.wsft)
- PréstamosCrédito – GuayabaCash (com.guayaba.cash.okredito.mx.tala)
- Préstamos De Crédito-YumiCash (com.loan.cash.credit.tala.prestmo.fast.branch.mextamo)
- Go Crédito – de confianza (com.mlo.xango)
- Instantaneo Préstamo (com.mmp.optima)
- Cartera grande (com.mxolp.postloan)
- Rápido Crédito (com.okey.prestamo)
- Finupp Lending (com.shuiyiwenhua.gl)
- 4S Cash (com.swefjjghs.weejteop)
- TrueNaira – Online Loan (com.truenaira.cashloan.moneycredit)
- EasyCash (king.credit.ng)
- safe loans (com.sc.safe.credit)
See more: SpyLoan apps – Google Play: Malicious apps with millions of downloads
SMS messages and social platforms such as Twitter, Facebook , and YouTube are major sources of spreading threats and malware. There are also apps available for download from scam websites and third-party app stores.
The apps are part of a larger scheme that began in 2020 involving more than 300 Android and iOS apps, uncovered last year by Kaspersky, Lookout and Zimperium. These apps exploited victims’ desire for instant money to lure borrowers into loan scams and demand access to sensitive information, such as contacts and SMS messages.

In addition to collecting information from compromised devices, users also employ blackmail and harassment tactics to pressure victims into making payments, threatening to post their photos and videos on social media platforms.
Source: thehackernews.com
