Malicious Android Loan Apps Steal Users Personal & Financial Information
There had been experiences of several Android loan apps that pretended to be offering loan companies and straight forward accessibility to funds, that own been discovered to be malicious apps that quiet private and monetary recordsdata from the victims.
These functions are identified as “SpyLoan” apps as they aquire users’ sensitive recordsdata and exercise them to extort cash. Better than 17 functions that had been accessible on Google Play had been discovered, reported, and as a consequence of this truth eradicated.
Per the experiences of those functions, the owners of those apps had been harassing customers even when the loan used to be no longer supplied to the users. The focused users of those apps had been essentially based in Southeast Asia, Africa, and Latin The US.
These functions had been dispensed among victims by means of social media, SMS messages, and rip-off web sites. It is miles important to narrate that each one in all those functions own the same behavior and functions.
The operators of those functions had been essentially from Mexico, Indonesia, Thailand, Vietnam, India, Pakistan, Colombia, Peru, the Philippines, Egypt, Kenya, Nigeria and Singapore.
Malicious Android Loan Apps
As soon as these apps are put in on the victim’s instrument, they are caused to honest accumulate the phrases of service and requested to possess too important permission on the instrument. These permissions enable users to accumulate entry to sensitive recordsdata on the instrument. A cell phone number registration process would possibly per chance be made to substantiate the person’s nation of enlighten.
To total the loan utility process, users are pressured to possess private recordsdata similar to contact recordsdata, address facts, proof of revenue, banking account recordsdata, and selfie confirmations.
Alongside with this recordsdata, these functions also aquire an inventory of accounts, name logs, calendar occasions, instrument recordsdata, put in functions checklist, native Wi-Fi community recordsdata, and various EXIF metadata of photography and photos on the instrument.
Recordsdata Exfiltration and Modus Operandi
This quiet recordsdata is then transferred to the C&C server with several ways like code obfuscation, encrypted strings, and encrypted dialog between the C2 server and the instrument.
Nonetheless, Google up as a lot as now its insurance policies on Google Play in Can also honest 2023, which prohibited functions from asking to accumulate entry to sensitive recordsdata like photography, videos, contacts, phone numbers, location, and storage accumulate entry to.
Even supposing this policy prohibited several functions from getting within Google Play, existing functions had been peaceable having all these permissions supplied.
Furthermore, the victims of those functions are threatened with extorting more cash from the utility operators. Most of those functions particularly affected inclined other folks in urgent want of cash and borrowers with restricted accumulate entry to to real monetary institutions.
A total file about all these malicious blackmailing functions has been printed, offering detailed recordsdata about the source code, operations, and others.
Indicators of Compromise
Files
SHA-1 | Filename | Detection | Description |
136067AC519C23EF7B9E8EB788D1F5366CCC5045 | com.aa.kredit.android.apk | Android/SpyLoan.AN | SpyLoan malware. |
C0A6755FF0CCA3F13E3C9980D68B77A835B15E89 | com.amorcash.credito.prestamo.apk | Android/SpyLoan.BE | SpyLoan malware. |
0951252E7052AB86208B4F42EB61FC40CA8A6E29 | com.app.lo.dawdle.apk | Android/Look for.Agent.CMO | SpyLoan malware. |
B4B43FD2E15FF54F8954BAC6EA69634701A96B96 | com.cashwow.cow.eg.apk | Android/Look for.Agent.EY | SpyLoan malware. |
D5104BB07965963B1B08731E22F00A5227C82AF5 | com.dinero.profin.prestamo.credito.credit score.credibus.loan.efectivo.cash.apk | Android/Look for.Agent.CLK | SpyLoan malware. |
F79D612398C1948DDC8C757F9892EFBE3D3F585D | com.flashloan.wsft.apk | Android/Look for.Agent.CNB | SpyLoan malware. |
C0D56B3A31F46A7C54C54ABEE0B0BBCE93B98BBC | com.guayaba.cash.okredito.mx.tala.apk | Android/Look for.Agent.CLK | SpyLoan malware. |
E5AC364C1C9F93599DE0F0ADC2CF9454F9FF1534 | com.loan.cash.credit score.tala.prestmo.like a flash.division.mextamo.apk | Android/SpyLoan.EZ | SpyLoan malware. |
9C430EBA0E50BD1395BB2E0D9DDED9A789138B46 | com.mlo.xango.apk | Android/Look for.Agent.CNA | SpyLoan malware. |
6DC453125C90E3FA53988288317E303038DB3AC6 | com.mmp.optima.apk | Android/Look for.Agent.CQX | SpyLoan malware. |
532D17F8F78FAB9DB953970E22910D17C14DDC75 | com.mxolp.postloan.apk | Android/Look for.KreditSpy.E | SpyLoan malware. |
720127B1920BA8508D0BBEBEA66C70EF0A4CBC37 | com.okey.prestamo.apk | Android/Look for.Agent.CNA | SpyLoan malware. |
2010B9D4471BC5D38CD98241A0AB1B5B40841D18 | com.shuiyiwenhua.gl.apk | Android/Look for.KreditSpy.C | SpyLoan malware. |
892CF1A5921D34F699691A67292C1C1FB36B45A8 | com.swefjjghs.weejteop.apk | Android/SpyLoan.EW | SpyLoan malware. |
690375AE4B7D5D425A881893D0D34BB63462DBBF | com.truenaira.cashloan.moneycredit.apk | Android/SpyLoan.FA | SpyLoan malware. |
1F01654928FC966334D658244F27215DB00BE097 | king.credit score.ng.apk | Android/SpyLoan.AH | SpyLoan malware. |
DF38021A7B0B162FA661DB9D390F038F6DC08F72 | om.sc.safe.credit score.apk | Android/Look for.Agent.CME | SpyLoan malware. |
Network
Enviornment | Web web hosting provider | First seen | Little print |
pss.aakredit[.]in | Amazon.com, Inc. | 2023-03-27 | C&C server. |
www.guayabacash[.]com | Amazon.com, Inc. | 2021-10-17 | C&C server. |
eg.easycredit-app[.]com | Amazon.com, Inc. | 2022-11-26 | C&C server. |
ag.ahymvoxxg[.]com | HUAWEI CLOUDS | 2022-05-28 | C&C server. |
hwpamjvk.whcashph[.]com | Alibaba (US) Expertise Co., Ltd. | 2020-01-22 | C&C server. |
qt.qtzhreop[.]com | Alibaba (US) Expertise Co., Ltd. | 2022-03-22 | C&C server. |
leisure.bhvbhgvh[.]condo | Alibaba (US) Expertise Co., Ltd. | 2021-10-26 | C&C server. |
la6gd.cashwow[.]membership | Alibaba (US) Expertise Co., Ltd. | 2022-10-28 | C&C server. |
mpx.mpxoptim[.]com | Alibaba (US) Expertise Co., Ltd. | 2023-04-24 | C&C server. |
oy.oyeqctus[.]com | ALICLOUD-US | 2023-01-27 | C&C server. |
iu.iuuaufbt[.]com | Alibaba (US) Expertise Co., Ltd. | 2022-03-01 | C&C server. |
kk.softheartlend2[.]com | IRT-HIPL-SG | 2023-01-28 | C&C server. |
www.credibusco[.]com | Amazon.com, Inc. | 2022-03-26 | C&C server. |
cy.amorcash[.]com | Cloudflare, Inc. | 2023-01-24 | C&C server. |
api.yumicash[.]com | HUAWEI CLOUDS | 2020-12-17 | C&C server. |
app.truenaira[.]co | IRT-UCLOUD-HK | 2021-10-18 | C&C server. |
apitai.coccash[.]com | Cloudflare, Inc. | 2021-10-21 | C&C server. |
Source credit : cybersecuritynews.com