Popular Android financial help app is actually dangerous malware

mobile phone
(Image credit: Shutterstock / ImYanis)

  • Researchers found a predatory loans app hiding as a financial management application
  • Android app apeared to exclusively target Indian users
  • It was removed from the Play Store

Cybersecurity researchers have found a SpyLoan app in Google Play targeting Indian consumers with some 100,000 downloads, before being pulled from the app store.

Predatory loan apps have a simple modus operandi: they advertise as quick and easy loan apps, offering fast loans with little to no paperwork. When the victim installs the app, though, it demands excessive permissions, accessing people’s messages and call logs, contacts, photos, and more.

After taking a loan, the app then asks for high interest rates, starts harassing the victim, and threatens to release sensitive photos (sometimes even fake, edited photos, too).

Bypassing security mechanisms with WebView

In this case, cybersecurity researchers from CYFIRMA found an app called Finance Simplified, which allegedly had 100,000 downloads on Google Play before being pulled down. This app pretended to be a financial management application, and while it worked more-or-less as intended around the world, it behaved differently for users located in India.

Before the app was pulled, BleepingComputer managed to read some of the reviews. "Very very very bad app they given low loan amount nd black mail to pay High otherwise photoes edited as a nude nd black mailing," one review read. CYFIRMA also said the app was advertised as a registered non-banking financial company, which was an outright lie.

Google is usually quite good at spotting malware in its repository, which begs the question - how did Finance Simplified make it through? Apparently, it loaded a WebView to redirect users to an external website, from where they downloaded a loan app APK hosted on an Amazon EC2 server.

"The Finance Simplified app appears to target Indian users specifically by displaying and recommending loan applications, loading a WebView that shows a loan service that redirects to an external website where a separate loan APK file is downloaded," CYFIRMA said.

After the news broke, a Google spokesperson said the app was removed from Google Play, and added that Android users are “automatically protected” against known versions of this malware by Google Play Protect. “Google Play Protect can warn users or block apps known to exhibit malicious behavior, even when those apps come from sources outside of Play,” the spokesperson told BleepingComputer.

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
App stores are increasingly becoming a major security worry
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
Android phone malware
This nasty Android malware is posing as the Telegram Premium app
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring