These dangerous Android malware apps have been installed millions of times

instant loan apps
(Image credit: Pexels / Andrea Piacquadio)

  • Researchers found 15 predatory loan apps on the Play Store
  • These apps promise cheap and quick loans, and then extort money and harass their victims
  • The apps have since been removed

Another set of malicious Android applications from the SpyLoan malware family were discovered, and subsequently removed, from the Google Play Store.

Unfortunately, by the time the 15 apps were identified and ousted, they amassed millions of installations around the world.

SpyLoan apps are also called “predatory loan apps.” They trick the victims into losing money in a somewhat different fashion. Once installed, they will still ask permission to gain access to things like contacts lists, SMS, camera, call logs, and the device’s location.

Targeting South America and Asia

The apps are advertised as personal finance software, promising users quick and flexible loans with low rates and minimal requirements.

These rates and requirements are fraudulent, and if the user accepts the service, they will end up paying high-interest rates. If they appeal, they will be harassed, blackmailed, and will even have their family members dragged into it, as well.

McAfee’s researchers found the 15 apps cumulatively had eight million downloads between them. The top four had a million installations each. The full list of malicious apps can be found on McAfee’s blog here.

The apps primarily targeted people in South America, Southeast Asia, and Africa. The top four apps, with four million downloads between them, were designed for users in Mexico, Colombia, and Senegal. Once the user installs the app, it will send a one-time passcode which it uses to identify the victim’s location, and thus decide whether to proceed or not.

The scariest part about this campaign is that the apps were found on Google’s official repository, the Play Store. Google is usually quite stringent when it comes to mobile apps, and quick to remove any offenders. As such, it has built a reputation of a trusted repository. These SpyLoan apps are another proof that consumers should not blindly trust anyone, not even Google, and should always verify.

To make sure an app is legitimate, make sure to check its rating, the number of downloads, and the reviews. Also, make sure the reviews aren’t randomly generated by bots. Ultimately, read a few lowest-rated reviews, to see what other users were most dissatisfied with.

Via BleepingComputer

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
mobile phone
Popular Android financial help app is actually dangerous malware
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
App stores are increasingly becoming a major security worry
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Over 2 million risky Android apps were blocked from the Play Store last year
Android phone malware
Screen reading malware found in iOS app stores for first time - and it might steal your cryptocurrency
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
Android phone malware
This nasty Android malware is posing as the Telegram Premium app
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off