Sunday, January 26, 2025
HomeAndroid50,000 times Downloaded Android Horror Game from GooglePlay Steals Google and Facebook...

50,000 times Downloaded Android Horror Game from GooglePlay Steals Google and Facebook Login Credentials

Published on

SIEM as a Service

Follow Us on Google News

Android Horror game uses malicious scripts to steal the user’s login credentials and uses ad networks to drive more traffic and cause damage to the affected device.

Wandera’s threat research team identified the malicious app on the Google Play Store. The app fools the Google Play Store’s rigorous security checks, “by using time-released malicious behavior, by using package names that closely resemble legitimate ones, and by being a fully functioning game, the game evaded suspicion and known red flags.”

Once it gets installed to the device, the app doesn’t start the infection process immediately; it stays calm for days before the malicious activity is triggered.

The app also targets victim’s based on the device operating systems, if the latest version of Android OS installed, it doesn’t perform any malicious activities, if it is an older version, then the malicious activity will get initiated.

Malicious Functions

On the infected victim device it popup’s fake notification asking the user to update Google security services, upon clicking update it presents a fake Google Login page and tricks victims into stealing passwords.

If the user enters the credentials, then it extracts additional information, including Recovery emails, Recovery phone numbers, Birthday, Verification codes, Cookies, and tokens. The app is also capable of launching itself after device reboot.

Based on Wandera analysis, the persistent ads displayed by the Scary Granny app opens the fake applications of the following service that includes Amazon, Facebook, Facebook Lite, HaGo, Hulu, Instagram, Messenger, Pinterest, SnapChat, TikTok, and Zalo.

“The app profits in two main ways: by trying to get the user to pay for the app, and by using ad networks. Upon installation, the game asks the user to pay for the game or to do a free trial. When the user selects the free trial, the app loads a pre-populated PayPal payment page for £18 ($22),” reads the blog post.

The apps download rate jumps from 1,000 to 50,000 within three weeks, and the game has a 4-star review. The malicious app has been taken down from the play store on June 27.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Also Read

Chinese APT 10 Group Hacked Nearly 10 Telecom Networks and Stealing Users Call Records, PII, Credentials, Email Data and more

Hackers Take Complete Control of Your Android Device by Launching MobOk Malware via Fake Photo Editing Apps in Google Play

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Subaru’s STARLINK Connected Car’s Vulnerability Let Attackers Gain Restricted Access

In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a...

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...

Juniper Routers Exploited via Magic Packet Vulnerability to Deploy Custom Backdoor

A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...

Beware of Fake Captcha Verifications Spreading Lumma Malware

In January, Netskope Threat Labs uncovered a sophisticated global malware campaign leveraging fake CAPTCHA...