HomeYoutubeGoogle Play: Over 100,000 users downloaded SpyLend malware

Google Play: Over 100,000 users downloaded SpyLend malware

A malware called SpyLend managed to infiltrate the Google Play Store, disguised as a financial tool, and acquired more than 100,000 users.

The app falls into a group of malicious Android apps called “SpyLoan.” These apps pose as legitimate financial tools or loan providers, but steal data from devices for use in “predatory lending.”

These apps lure users with promises of quick and easy loans and attractive terms. However, upon installation, they request excessive permissions, which they exploit to steal personal data such as contacts, call logs, SMS messages, photos, and location data.

This information is then used to harass and blackmail users, especially if they do not meet the repayment terms.

See also: Salt Typhoon uses custom malware JumbledPath in attacks

SpyLend malware Google Play

Loan scams

Cybersecurity firm CYFIRMA discovered an app on Google Play called “Finance Simplified,” which claims to be a financial management app and has 100,000 downloads, but actually includes the information-stealing SpyLend malware.

According to researchers, the malicious behavior of the app is occurring in some countries, such as India, and is stealing data devices users'

Researchers say they discovered additional malicious APKs that appear to be variants of the same malware campaign (KreditApple, PokketMe, and StashFur).

Although the app has now been removed from Google Play, it can continue to run in the background, collecting sensitive information from infected devices. User reviews of Finance Simplified have reported that the app offers lending services that attempt to extort borrowers if they do not pay high interest rates.

The malicious apps, which include the SpyLend malware, also claim to be registered Non-Banking Financial Companies (NBFCs), which CYFIRMA says is untrue.

See also: Zhong Malware exploits AnyDesk for attacks

The Finance Simplified app managed to evade Google Play checks by loading a WebView that redirects users to an external website where they download a loan app APK hosted on an Amazon EC2 server.

Researchers discovered that the app will only load the misleading interface if the user's location is India, indicating that the campaign is targeted.

SpyLend malware steals user data

The most worrying aspect of the malware's activity is the collection of sensitive data stored on the user's device.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Specifically, the malware steals:

  • Contacts, call logs, SMS messages and device details.
  • Photos, videos and documents from internal and external storage.
  • Real-time location data (updated every 3 seconds), historical location data and IP address.
  • Last 20 text entries copied to the clipboard.
  • Loan history and SMS banking transaction messages.

Although this data is mainly used to blackmail victims who applied for a loan, it can also be used for financial fraud or resold to cybercriminals.

Finance Simplified
Google Play: Over 100,000 users downloaded SpyLend malware

Protection from malicious applications

If you suspect your device has been infected by any of the above apps, delete it immediately, change your bank account passwords, and scan your device.

You should always verify the authenticity of an app before installing it. This can be done reviews user.

See also: Beware! New advanced variant of Snake Keylogger malware

Additionally, visit the official website of a service and find the link there to download the application from the app store.

It's also important to check the permissions that apps request, even if they're on Google Play. If an app asks for access to personal information that doesn't seem necessary for it to function, it's best to avoid installing it.

The use of reliable security software and regular updates of the operating system and applications are also essential  

Finally, don't forget that Google's Play Protect tool detects and blocks known malware and aggressive apps, so make sure it's active on your device.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS