SpyLoan: A Global Threat Exploiting Social Engineering
ID: 858c5050-36e3-53e3-b30f-e8ef569b45bb
STIX ID: report--858c5050-36e3-53e3-b30f-e8ef569b45bb
Feed Name: McAfee Labs Blog
McAfee Mobile Research documents a global surge of SpyLoan Android apps — predatory loan applications distributed via Google Play that request excessive permissions, harvest sensitive personal and device data, encrypt and exfiltrate it to hardcoded C2 endpoints, and are used to harass and extort victims; the report includes technical analysis (AES usage with hardcoded keys, C2 URL regex), IOCs (package names and SHA256 hashes), regional telemetry (millions of installs concentrated in South America, Southeast Asia and Africa), user impact examples, law enforcement actions, and protection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
