{"id":28593,"date":"2024-12-04T12:52:00","date_gmt":"2024-12-04T12:52:00","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=28593"},"modified":"2024-12-04T12:52:00","modified_gmt":"2024-12-04T12:52:00","slug":"spyloan-malware-google-play-store","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/spyloan-malware-google-play-store\/","title":{"rendered":"SpyLoan Virus Found in Loan Apps on Google Play Store"},"content":{"rendered":"<p>Experts reported the discovery of a new set of <strong>15 malicious mobile apps in the Google Play store<\/strong> that contain the SpyLoan Android malware inside. In total, these apps have been downloaded and installed by users more than 8 million times, potentially leading to huge money losses.<\/p>\n<h2>8 Million Android Users Hit by SpyLoan Malware in Loan Apps on Google Play<\/h2>\n<p>Researchers have found <a href=\"https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/spyloan-a-global-threat-exploiting-social-engineering\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">a series of malicious apps<\/a> on the Google Play Store. Collectively, these programs have been installed <strong>over 8 million times<\/strong>. These apps pose as quick-loan services, exploiting users\u2019 need for money under the guise of financial assistance. Instead of what they state, these fake loan apps collect sensitive data and further intimidate victims.<\/p>\n<p>The malware identified in the majority of these samples is <strong>SpyLoan<\/strong>. Initially detected in 2020, it has resurfaced with updated tactics, with another noteworthy appearance in 2023. It now targets users in countries such as Mexico, Colombia, Thailand, and Tanzania.<\/p>\n<figure id=\"attachment_28599\" aria-describedby=\"caption-attachment-28599\" style=\"width: 1209px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/SpyLoan-apps-on-Google-Play.webp\" alt=\"SpyLoan apps screenshot\" width=\"1209\" height=\"680\" class=\"size-full wp-image-28599\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/SpyLoan-apps-on-Google-Play.webp 1209w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/SpyLoan-apps-on-Google-Play-300x169.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/SpyLoan-apps-on-Google-Play-1024x576.webp 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/SpyLoan-apps-on-Google-Play-768x432.webp 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/SpyLoan-apps-on-Google-Play-860x484.webp 860w\" sizes=\"auto, (max-width: 1209px) 100vw, 1209px\" \/><figcaption id=\"caption-attachment-28599\" class=\"wp-caption-text\">Examples of SpyLoan apps recently distributed on Google Play (source: McAfee)<\/figcaption><\/figure>\n<p>As the name implies, SpyLoan mainly hides under the guise of loan-related apps. Its goal is to \u0441ollect sensitive user data, exploit permissions to access phone features and coerce users through intimidation or extortion. The user may get the loan, but will also get phishing phone calls, SMS messages and emails, all with the potential of financial damage and psychological abuse.<\/p>\n<h2>How the Malware Operates<\/h2>\n<p>SpyLoan malware operates by tricking users into sharing personal and financial information. The apps use <a href=\"https:\/\/gridinsoft.com\/social-engineering\">social engineering tactics<\/a> to request extensive permissions, such as access to contacts, call logs, SMS, and device location.<\/p>\n<p>Although these permissions are justified as part of anti-fraud measures, in reality, they enable the malware to harvest data from the device. Once collected, the data is encrypted using AES-128 and sent to a command server. This encryption stage, although employing a pretty weak algorithm, makes it hard to parse the data transfer and recognize it as malicious.<\/p>\n<p>Victims are lured into these apps with promises of fast and easy loans, targeting regions such as Mexico, Colombia, Thailand, and Tanzania. However, instead of providing legitimate financial services, users see <strong>high interest rates and huge penalties<\/strong> for payment delays.<\/p>\n<p>Moreover, <strong>cybercriminals start threatening victims with time<\/strong>; threats involving their personal data and photos, most likely stolen through the SpyLoan functionality. This malicious cycle traps users in debt while violating their privacy. The malicious apps, targeting regions across South America, Africa, and Southeast Asia, include:<\/p>\n<ul>\n<li>Pr\u00e9stamo Seguro-R\u00e1pido, seguro<\/li>\n<li>RupiahKilat-Dana cair<\/li>\n<li>\u00c9coPr\u00eat Pr\u00eat En Ligne<\/li>\n<li>\u0e22\u0e37\u0e21\u0e2d\u0e22\u0e48\u0e32\u0e07\u0e21\u0e35\u0e04\u0e27\u0e32\u0e21\u0e2a\u0e38\u0e02 \u2013 \u0e40\u0e07\u0e34\u0e19\u0e01\u0e39\u0e49<\/li>\n<li>Huayna Money \u2013 Pr\u00e9stamo R\u00e1pido<\/li>\n<\/ul>\n<p>While some apps have been removed or modified to comply with Google Play policies, five of these are still available for download. I expect them to be gone pretty soon, too, but publishing new ones appears to be a rather simple task. <strong>Google should pay a lot of attention to its security mechanisms<\/strong>, to say the least. We have several older news articles about the <a href=\"https:\/\/gridinsoft.com\/blogs\/google-play-malware\/\">malware in Play Store<\/a> &#8211; consider checking them out.<\/p>\n<h2>How to Stay Safe?<\/h2>\n<p>The apps rely on a shared framework, suggesting a common developer or toolkit that cybercriminals use globally. By tailoring the user experience to local cultures and regulations, these apps effectively infiltrate diverse markets. However, SpyLoan is not a new threat; its operations date back to 2020, with previous reports revealing similar tactics and outcomes. I&#8217;ve written <a href=\"https:\/\/gridinsoft.com\/blogs\/malicious-loan-apps\/\">about this before<\/a>.<\/p>\n<p>To protect against threats like SpyLoan, you should <strong>carefully review app permissions<\/strong>, check the legitimacy of developers, and read app reviews. Additionally, users should avoid downloading apps promoted through unverified social media posts.<\/p>\n<figure id=\"attachment_28602\" aria-describedby=\"caption-attachment-28602\" style=\"width: 949px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Comments-on-GP.webp\" alt=\"Comments on SpyLoan apps\" width=\"949\" height=\"612\" class=\"size-full wp-image-28602\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Comments-on-GP.webp 949w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Comments-on-GP-300x193.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Comments-on-GP-768x495.webp 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Comments-on-GP-860x555.webp 860w\" sizes=\"auto, (max-width: 949px) 100vw, 949px\" \/><figcaption id=\"caption-attachment-28602\" class=\"wp-caption-text\">Comments on SpyLoan apps on Google Play (source: McAfee)<\/figcaption><\/figure>\n<p>For advanced protection that will recognize even well-concealed threats, consider using <a href=\"https:\/\/gridinsoft.com\/android\">GridinSoft Trojan Scanner<\/a>. This free anti-malware program for Android provides all the necessary scanning and malware removal capabilities to keep your system safe.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Experts reported the discovery of a new set of 15 malicious mobile apps in the Google Play store that contain the SpyLoan Android malware inside. In total, these apps have been downloaded and installed by users more than 8 million times, potentially leading to huge money losses. 8 Million Android Users Hit by SpyLoan Malware [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":28604,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[6,15],"tags":[114,247,48],"class_list":{"0":"post-28593","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-mobile-security","8":"category-security-news","9":"tag-android","10":"tag-google-play-store","11":"tag-spyware"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/SpyLoan-Malware-in-Loan-Apps-on-Google-Play.webp","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/28593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=28593"}],"version-history":[{"count":13,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/28593\/revisions"}],"predecessor-version":[{"id":28611,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/28593\/revisions\/28611"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/28604"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=28593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=28593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=28593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}