logo

Beware of predatory fin(tech): Loan sharks use Android apps to reach new depths

ID: 941f47b6-7539-55ad-847b-a898f0327b94

STIX ID: report--941f47b6-7539-55ad-847b-a898f0327b94

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
72/100

Date Published: 2023-12-05

Date Updated: 2026-05-01

...
...

ESET researchers describe the SpyLoan campaign: fraudulent Android loan apps distributed via social media, SMS, third‑party stores and Google Play that request broad permissions, harvest sensitive data, and exfiltrate it to C2 servers; victims across Southeast Asia, Africa, and Latin America report harassment, blackmail, and predatory loan practices. The report provides technical analysis, MITRE ATT&CK mapping, IoCs (SHA-1 hashes, C2 IPs/domains), and user-protection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.