logo

SpyLoan Android malware on Google play installed 8 million times

ID: 80ac43ae-3b01-5789-9ad7-6ac152c52deb

STIX ID: report--80ac43ae-3b01-5789-9ad7-6ac152c52deb

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-30

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A set of 15 malicious "SpyLoan" Android apps were discovered on Google Play with over 8 million installs; they posed as loan services, collected OTPs and sensitive documents, and abused device permissions to exfiltrate SMS, contacts, call logs, camera, location, and banking information to enable extortion and harassment of victims across South America, Southeast Asia, and Africa. McAfee identified and reported the apps, which have since been removed, but their repeated appearance on the Play Store highlights ongoing risk and targeting of vulnerable users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.