50,000 times Downloaded Android Horror Game from GooglePlay Steals Google and Facebook Login Credentials

Android Horror game uses malicious scripts to steal the user’s login credentials and uses ad networks to drive more traffic and cause damage to the affected device.

Wandera’s threat research team identified the malicious app on the Google Play Store. The app fools the Google Play Store’s rigorous security checks, “by using time-released malicious behavior, by using package names that closely resemble legitimate ones, and by being a fully functioning game, the game evaded suspicion and known red flags.”

Once it gets installed to the device, the app doesn’t start the infection process immediately; it stays calm for days before the malicious activity is triggered.

The app also targets victim’s based on the device operating systems, if the latest version of Android OS installed, it doesn’t perform any malicious activities, if it is an older version, then the malicious activity will get initiated.

Malicious Functions

On the infected victim device it popup’s fake notification asking the user to update Google security services, upon clicking update it presents a fake Google Login page and tricks victims into stealing passwords.

If the user enters the credentials, then it extracts additional information, including Recovery emails, Recovery phone numbers, Birthday, Verification codes, Cookies, and tokens. The app is also capable of launching itself after device reboot.

Based on Wandera analysis, the persistent ads displayed by the Scary Granny app opens the fake applications of the following service that includes Amazon, Facebook, Facebook Lite, HaGo, Hulu, Instagram, Messenger, Pinterest, SnapChat, TikTok, and Zalo.

“The app profits in two main ways: by trying to get the user to pay for the app, and by using ad networks. Upon installation, the game asks the user to pay for the game or to do a free trial. When the user selects the free trial, the app loads a pre-populated PayPal payment page for £18 ($22),” reads the blog post.

The apps download rate jumps from 1,000 to 50,000 within three weeks, and the game has a 4-star review. The malicious app has been taken down from the play store on June 27.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Also Read

Chinese APT 10 Group Hacked Nearly 10 Telecom Networks and Stealing Users Call Records, PII, Credentials, Email Data and more

Hackers Take Complete Control of Your Android Device by Launching MobOk Malware via Fake Photo Editing Apps in Google Play

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS devices.…

23 hours ago

ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues

White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch Experts…

3 days ago

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan exploits…

3 days ago

Konni APT Hackers Attacking Organizations with New Spear-Phishing Tactics

The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on organizations…

3 days ago

Google Chrome Security, Critical Vulnerabilities Patched

Google has updated its Chrome browser, addressing critical vulnerabilities that posed potential risks to millions…

3 days ago

Notorious WrnRAT Delivered Mimic As Gambling Games

WrnRAT is a new malware attack that cybercriminals have deployed by using popular gambling games…

4 days ago