Malicious Android Loan Apps Steal Users Personal & Financial Information

by Esmeralda McKenzie
Malicious Android Loan Apps Steal Users Personal & Financial Information

Malicious Android Loan Apps Steal Users Personal & Financial Information

Malicious Android Loan Apps

There had been experiences of several Android loan apps that pretended to be offering loan companies and straight forward accessibility to funds, that own been discovered to be malicious apps that quiet private and monetary recordsdata from the victims.

These functions are identified as “SpyLoan” apps as they aquire users’ sensitive recordsdata and exercise them to extort cash. Better than 17 functions that had been accessible on Google Play had been discovered, reported, and as a consequence of this truth eradicated.

EHA

Per the experiences of those functions, the owners of those apps had been harassing customers even when the loan used to be no longer supplied to the users. The focused users of those apps had been essentially based in Southeast Asia, Africa, and Latin The US.

These functions had been dispensed among victims by means of social media, SMS messages, and rip-off web sites. It is miles important to narrate that each one in all those functions own the same behavior and functions.

The operators of those functions had been essentially from Mexico, Indonesia, Thailand, Vietnam, India, Pakistan, Colombia, Peru, the Philippines, Egypt, Kenya, Nigeria and Singapore.

Malicious Android Loan Apps

As soon as these apps are put in on the victim’s instrument, they are caused to honest accumulate the phrases of service and requested to possess too important permission on the instrument. These permissions enable users to accumulate entry to sensitive recordsdata on the instrument. A cell phone number registration process would possibly per chance be made to substantiate the person’s nation of enlighten.

To total the loan utility process, users are pressured to possess private recordsdata similar to contact recordsdata, address facts, proof of revenue, banking account recordsdata, and selfie confirmations.

Code for Extracting Permission (Source: ESET)

Alongside with this recordsdata, these functions also aquire an inventory of accounts, name logs, calendar occasions, instrument recordsdata, put in functions checklist, native Wi-Fi community recordsdata, and various EXIF metadata of photography and photos on the instrument.

Recordsdata Exfiltration and Modus Operandi

This quiet recordsdata is then transferred to the C&C server with several ways like code obfuscation, encrypted strings, and encrypted dialog between the C2 server and the instrument.

Nonetheless, Google up as a lot as now its insurance policies on Google Play in Can also honest 2023, which prohibited functions from asking to accumulate entry to sensitive recordsdata like photography, videos, contacts, phone numbers, location, and storage accumulate entry to.

Even supposing this policy prohibited several functions from getting within Google Play, existing functions had been peaceable having all these permissions supplied.

Furthermore, the victims of those functions are threatened with extorting more cash from the utility operators. Most of those functions particularly affected inclined other folks in urgent want of cash and borrowers with restricted accumulate entry to to real monetary institutions.

TevsRSr jYlyIuX1pYcEgO2QoPNZyA8ZYCIqzGs s1gs3cOpAji7e39gufggw6vZYSKOjF kXrg0R0tiAcztiJ
Reviews about Blackmail and threats (Source: ESET)

A total file about all these malicious blackmailing functions has been printed, offering detailed recordsdata about the source code, operations, and others.

Indicators of Compromise

Files

SHA-1 Filename Detection Description
136067AC519C23EF7B9E8EB788D1F5366CCC5045 com.aa.kredit.android.apk Android/SpyLoan.AN SpyLoan malware.
C0A6755FF0CCA3F13E3C9980D68B77A835B15E89 com.amorcash.credito.prestamo.apk Android/SpyLoan.BE SpyLoan malware.
0951252E7052AB86208B4F42EB61FC40CA8A6E29 com.app.lo.dawdle.apk Android/Look for.Agent.CMO SpyLoan malware.
B4B43FD2E15FF54F8954BAC6EA69634701A96B96 com.cashwow.cow.eg.apk Android/Look for.Agent.EY SpyLoan malware.
D5104BB07965963B1B08731E22F00A5227C82AF5 com.dinero.profin.prestamo.credito.credit score.credibus.loan.efectivo.cash.apk Android/Look for.Agent.CLK SpyLoan malware.
F79D612398C1948DDC8C757F9892EFBE3D3F585D com.flashloan.wsft.apk Android/Look for.Agent.CNB SpyLoan malware.
C0D56B3A31F46A7C54C54ABEE0B0BBCE93B98BBC com.guayaba.cash.okredito.mx.tala.apk Android/Look for.Agent.CLK SpyLoan malware.
E5AC364C1C9F93599DE0F0ADC2CF9454F9FF1534 com.loan.cash.credit score.tala.prestmo.like a flash.division.mextamo.apk Android/SpyLoan.EZ SpyLoan malware.
9C430EBA0E50BD1395BB2E0D9DDED9A789138B46 com.mlo.xango.apk Android/Look for.Agent.CNA SpyLoan malware.
6DC453125C90E3FA53988288317E303038DB3AC6 com.mmp.optima.apk Android/Look for.Agent.CQX SpyLoan malware.
532D17F8F78FAB9DB953970E22910D17C14DDC75 com.mxolp.postloan.apk Android/Look for.KreditSpy.E SpyLoan malware.
720127B1920BA8508D0BBEBEA66C70EF0A4CBC37 com.okey.prestamo.apk Android/Look for.Agent.CNA SpyLoan malware.
2010B9D4471BC5D38CD98241A0AB1B5B40841D18 com.shuiyiwenhua.gl.apk Android/Look for.KreditSpy.C SpyLoan malware.
892CF1A5921D34F699691A67292C1C1FB36B45A8 com.swefjjghs.weejteop.apk Android/SpyLoan.EW SpyLoan malware.
690375AE4B7D5D425A881893D0D34BB63462DBBF com.truenaira.cashloan.moneycredit.apk Android/SpyLoan.FA SpyLoan malware.
1F01654928FC966334D658244F27215DB00BE097 king.credit score.ng.apk Android/SpyLoan.AH SpyLoan malware.
DF38021A7B0B162FA661DB9D390F038F6DC08F72 om.sc.safe.credit score.apk Android/Look for.Agent.CME SpyLoan malware.

Network

Enviornment Web web hosting provider First seen Little print
pss.aakredit[.]in Amazon.com, Inc. 2023-03-27 C&C server.
www.guayabacash[.]com Amazon.com, Inc. 2021-10-17 C&C server.
eg.easycredit-app[.]com Amazon.com, Inc. 2022-11-26 C&C server.
ag.ahymvoxxg[.]com HUAWEI CLOUDS 2022-05-28 C&C server.
hwpamjvk.whcashph[.]com Alibaba (US) Expertise Co., Ltd. 2020-01-22 C&C server.
qt.qtzhreop[.]com Alibaba (US) Expertise Co., Ltd. 2022-03-22 C&C server.
leisure.bhvbhgvh[.]condo Alibaba (US) Expertise Co., Ltd. 2021-10-26 C&C server.
la6gd.cashwow[.]membership Alibaba (US) Expertise Co., Ltd. 2022-10-28 C&C server.
mpx.mpxoptim[.]com Alibaba (US) Expertise Co., Ltd. 2023-04-24 C&C server.
oy.oyeqctus[.]com ALICLOUD-US 2023-01-27 C&C server.
iu.iuuaufbt[.]com Alibaba (US) Expertise Co., Ltd. 2022-03-01 C&C server.
kk.softheartlend2[.]com IRT-HIPL-SG 2023-01-28 C&C server.
www.credibusco[.]com Amazon.com, Inc. 2022-03-26 C&C server.
cy.amorcash[.]com Cloudflare, Inc. 2023-01-24 C&C server.
api.yumicash[.]com HUAWEI CLOUDS 2020-12-17 C&C server.
app.truenaira[.]co IRT-UCLOUD-HK 2021-10-18 C&C server.
apitai.coccash[.]com Cloudflare, Inc. 2021-10-21 C&C server.

Source credit : cybersecuritynews.com

Related Posts