SpyLend Android Malware found on Google Play Store
John Davies
Malloc
SpyLend is a highly dangerous and deceptive threat targeting Android users. It is presented as a harmless finance management application on the Google Play Store, disguised as Finance Simplified (package: com.someca.count). The app downloads a fraudulent loan app from an external download URL, which, once installed, gains extensive permissions to access sensitive data, including call logs, SMS, contacts, files, clipboard content, and the camera. Attackers used these permissions for data exfiltration to extort users by creating deepfake photos from the manipulation of files in their photo gallery.
The app showed a significant surge in downloads, increasing from 50,000 to 100,000 within a single week, and had numerous negative reviews, with users complaining about the misuse of personal data, harassment and blackmailing, as well as the creation of deepfake images from the users' personal photos, which were accessible to the malware due to all kinds of permissions demanded by the app.
The admin command and control (C2) panel of the app, hosted on Amazon EC2 servers, supports two languages — English and Chinese — indicating that the malicious apps were managed by Chinese threat actors.
The Malicious Nature of SpyLend Malware
- SpyLend, disguised as Finance Simplified, acts as a gateway to predatory loan application apps like KreditPro, MoneyAPE, StashFur, Fairbalance, and PokketMe.
- The app initially presents itself as a legitimate finance calculator but dynamically alters its interface based on the user's geolocation, targeting users in India.
- Leveraging location-based targeting, the app displays a list of unauthorized loan apps that operate entirely within WebView and allows the attackers to bypass Play Store scrutiny.
- Once these loan apps are installed, they employ blackmail tactics to extort money, harvest sensitive user data, and enforce exploitative lending practices.
The Key Highlights of SpyLend Malware
- Play Store: SpyLend malware was made available through the Google Play Store.
- Popular: It was a fairly popular application, amassing 100,000 downloads.
- Negative Reviews: The app had numerous negative reviews, and users complained of data collection, harassment, extortion, and blackmailing.
- Functionality: The app was marketed as a financial loan calculator, but when users' locations were detected to be in India, the app changed its functionality and interface via Android WebView.
- External Privacy Policy: The app loads external content and displays its privacy policy via WebView. This approach poses a significant security risk. Since the privacy policy is served dynamically from an external URL, the attacker can modify the policy at any time, even after the app has been installed. This means the privacy policy can be altered without the user's knowledge, which, according to researchers, is a clear indication of malicious intent.
- External APK Downloads: To bypass Google Play Store's security checks, the app redirects users to external links to download APK files.
- Permissions and Malicious Access: After installing the malicious APKs, the app harasses users by accessing and misusing their photos, videos, and contacts. It captures clipboard text, potentially exposing sensitive information such as passwords, credit card details, and other private data.
- Use of APIs for Malicious Activities: The app leverages various APIs to perform harmful actions, like downloading and uploading files — including pictures — and accessing the list of installed applications, contacts, call history, and SMS.
- Blackmail and Extortion: After collecting sensitive personal data from users, attackers threaten and harass victims by editing their photos to create fake images to illegally extort money from victims.
List of Data Stolen by SpyLend Malware
According to researchers, SpyLend malware exfiltrates the following data from affected users:
- Contacts, call logs, SMS messages, and device details — call log access risks exposing communication patterns, leading to harassment or phishing.
- Photos, videos, and documents from internal and external storage — read/write access to external storage, justified for document storage, could allow manipulation, deletion, or exfiltration of sensitive files, severely compromising user privacy and security.
- Access to the camera — claimed to be for identity verification, it enables unauthorized photo capture or surveillance.
- Live location tracking — access to live location (updated every 3 seconds), historical location data, and IP address allows tracking of user movements, potentially for data sale or scams.
- Last 20 text entries copied to the clipboard — potentially exposing sensitive information such as passwords, credit card details, and other private data.
- Loan history and banking SMS transaction messages — this provides access to the victim's financial records, such as loan history, repayment details, and overdue payments. This information can be used to manipulate financial transactions or steal money.
How to Stay Safe from SpyLend Malware
According to Google, the app has been removed from Google Play. To stay safe from SpyLend malware and similar threats:
- Avoid downloading apps from untrusted sources.
- Check app reviews and look for signs of fraudulent app behaviour.
- Carefully review app permissions.
- Be cautious of apps that demand or request excessive access to personal data.
- Keep your mobile devices updated.
Lastly, use an effective security app from a reputable company, such as our app Malloc, available for Android and iOS. Malloc helps secure your mobile phone and helps protect you from threats like SpyLend malware. It scans the device through its security scan and alerts users to malicious apps and the permissions they require. It also detects the use of the device camera in the background by malware like SpyLend and alerts users to background microphone access on Android. Malloc also blocks trackers and insecure HTTP traffic, and comes equipped with a VPN for privacy and security. It detects and reduces risk; it is not a guarantee against every threat. More on the wider mobile security picture is here.
References: CYFIRMA — SpyLend: The Android App Available on Google Play Store; BleepingComputer — SpyLend Android malware downloaded 100,000 times from Google Play.
Relevant tags:
Published on Medium