McAfee researchers have discovered 15 malicious apps on Google Play that have been downloaded more than 8 million times and are infecting users with the Android malware SpyLoan . The apps are primarily targeting users in South America, Southeast Asia, and Africa.

The apps have now been removed from Google’s official app store. However, their initial entry into Google Play and millions of downloads show that scammers are still bypassing security measures and gaining access to official stores. Also, although law enforcement has taken action against the operators of SpyLoan, the problem has not been contained.
The last major “SpyLoan purge” on Google Play was in December 2023, when over a dozen apps with 12 million downloads.
See also: New Skimmer malware steals credit card data
SpyLoan Android malware
SpyLoan is usually included in applications that are presented as financial tools that offer users loans through a supposedly quick approval process.
Once victims install the malicious apps, they are authenticated via a one-time password (OTP) to ensure they are in the targeted region. They are then asked to submit sensitive identification documents, work details, and bank account details.
Additionally, apps abuse their device permissions to collect sensitive data (contacts, SMS, camera, call log, and location).
McAfee notes that these apps' aggressive data collection extend to extracting all SMS messages, as well as GPS/network location, device information, operating system details, and sensor data.
See also: NordLayer adds malware detection tool
Once a user receives a loan through the app, they are locked into high-interest payments and regularly harassed by the operators of the SpyLoan Android malware, who use the stolen data to blackmail them. In some cases, the scammers call the user's family members, harassing them as well.
8 million downloads on Google Play
McAfee's research identified 15 malicious SpyLoan apps, which have been installed over 8 million times through the Play Store alone. The most popular apps are:
- Préstamo Seguro-Rápido, Seguro – 1,000,000 downloads, mainly targeting Mexico
- Préstamo Rápido-Credit Easy – 1,000,000 downloads, mainly targeting Colombia
- คล้ว่วั่วิตั่ว้ว้ย่าวิ่ว้า – 1,000,000 downloads, mainly targeting Senegal
- RupiahKilat-Dana cair – 1,000,000 downloads, mainly targeting Senegal
- สัววับติต้าว – วับต้า – 1,000,000 downloads, mainly targeting Thailand
- Happy Money – Quick Loans – 1,000,000 downloads, mainly targeting Thailand
- KreditKu-Uang Online – 500,000 downloads, mainly targeting Indonesia
- Dana Kilat-Pinjaman kecil – 500,000 downloads, mainly targeting Indonesia

Despite Google's control mechanisms to block malware, SpyLoan apps continue to infiltrate the store.
Protection from malicious applications
Although Google Play has defense mechanisms, some malicious apps manage to sneak into the store. For this reason, users should always verify the authenticity of an app before installing it. This can be done reviews user.
Additionally, users can visit the official website of a service and find the link there to download the application from the app store.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: PixPirate malware attacks users via WhatsApp
It's also important to check the permissions that apps request, even if they're on Google Play. If an app asks for access to personal information that doesn't seem necessary for it to function, it's best to avoid installing it.
It is also essential to use reliable security software and regularly update the operating system and applications. Finally, users should avoid sharing their personal information with untrusted sources.
Source: www.bleepingcomputer.com
