×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • SpyLoan Fraudulent Apps: ESET Spots Expansion of Reach to Android

Customer Press Room

SpyLoan Fraudulent Apps: ESET Spots Expansion of Reach to Android

by Grandangolo Communications / Monday, 11 December 2023 / Published in Eset

The apps solicit sensitive information from users and exfiltrate it into attackers' servers for blackmail. ESET telemetry shows clear growth of these apps in unofficial third-party app stores, Google Play and websites since early 2023

Researchers of ESET, a global European leader in the cybersecurity market, have observed an alarming growth in 2023 in fraudulent Android lending apps, which present themselves as legitimate personal loan services, promising quick and easy access to funds. Despite their attractive appearance, these services are actually designed to defraud users by offering them high-interest loans accompanied by misleading descriptions, all while collecting victims' personal and financial information for blackmail. ESET's systems then recognize these applications with the detection name SpyLoan, which directly refers to their spyware functionality combined with loan requests. SpyLoan apps are spread through social media and SMS messages and are available for download from scam websites, third-party app stores, and even Google Play.

ESET is a member of the App Defense Alliance (ADA) and an active partner in the Malware mitigation program, which aims to quickly identify potentially harmful applications and block them before they land on Google Play. As a member of the ADA, ESET identified 18 SpyLoan applications and reported them to Google, which subsequently removed 17 of them from its platform. These apps had a total of over 12 million downloads from Google Play before their removal. The last app listed has changed its behavior; ESET no longer detects it as a SpyLoan app.

Each instance of a particular SpyLoan app, regardless of origin, behaves identically thanks to a common code base. It doesn't matter if the download comes from a suspicious website, a third-party app store, or even Google Play: users will experience the same features and run the same risks, regardless of where the app comes from.

According to ESET telemetry, the creators of these apps, which blackmail and harass their victims, including with death threats, operate mainly in Mexico, Indonesia, Thailand, Vietnam, India, Pakistan, Colombia, Peru, the Philippines, Egypt, Kenya, Nigeria and Singapore. ESET researchers believe that any detections outside of these countries are linked to smartphones that, for various reasons, have access to a phone number registered in one of these countries. At the moment there are no active campaigns aimed at European countries, the United States or Canada.

In addition to data collection and blackmail, these services present a form of modern digital usury, which refers to the charging of exorbitant interest rates on loans, taking advantage of vulnerable individuals. Victims of these apps report that the total annual cost (CTA) of these loans is much higher than agreed and the duration of the loan is much shorter than agreed. In some cases, borrowers were pressured to repay their loans in five days, instead of the expected 91 days, and the CTA of a loan was between 160% and 340%.

“These fraudulent apps exploit the trust users place in legitimate loan providers, using sophisticated techniques to deceive people and steal a wide range of personal information,” explains Lukáš Štefanko, ESET researcher who discovered many of the SpyLoan applications. “It is vital that individuals exercise caution, validate the authenticity of any financial app or service, and rely on trusted sources. By staying informed and vigilant, users they can better protect themselves from the risk of falling victim to these deceptive schemes,” he adds.

ESET Research reconstructed the origins of the SpyLoan scheme in 2020. Once the user installs a SpyLoan app, they are asked to accept the terms of service and grant broad permissions to access sensitive data stored on the device. According to the privacy policies of these apps, if these permissions are not granted, the loan is not disbursed. To complete the loan application process, users are also forced to provide numerous personal information.

The data that is usually exfiltrated to the Command & Control (C&C) server includes the user's account list, call logs, calendar events, device information, installed app lists, local Wi-Fi network information, and even information about files on the device. Additionally, contact lists, location data, and SMS messages are exposed. To protect their activities, criminals encrypt all stolen data before transmitting it to the C&C server. Although legitimate financial institutions are required to collect personal information about their customers, identity verification and risk assessment can be done using much less invasive data collection methods. ESET Research believes that the true purpose of the permissions requested by SpyLoan apps is to spy on users and blackmail both them and their contacts.

After installing the app and collecting personal data, those responsible for the application begin to pressure victims into making payments, even if, according to reviews, the user has not requested a loan or has requested one but has not been approved. These practices have been described in reviews of these apps on Facebook and Google Play.

"There are several reasons behind the rapid growth of SpyLoan apps. One of them is that the developers of these apps are inspired by successful FinTech (financial technology) services, which leverage technology to provide simplified and easy-to-use financial services," explains Štefanko.

Tagged under: Android, Eset

About Grandangolo Communications

What you can read next

Working in Abstract means having the opportunity to evolve both in professional skills and in managerial management. The new internal organization, which makes the approach to the project the priority over any other phase of the work, ensures that every Abstract professional has the means to manage the activity independently, while learning to use new and innovative technologies. frontier required by the market today.
ESET complete the selection of authorized distributors in Italy
ESET discovers a new campaign by MuddyWater against critical infrastructure in Israel and Egypt, disguised as a Snake application

Customer Press Room

  • Vertiv introduces backup power for personal devices and business applications

    Vertiv™ PowerUPS 200 Series is a ...
  • Sandworm Group Hits Energy Company in Poland with DynoWiper: ESET Research Analysis

    ESET researchers have identified DynoWip...
  • Antonio Menghini is the new Chief Commercial Officer of Innovaway

    At the same time, Giuseppe Piccolo took over ...
  • Vertiv introduces a new AI-powered predictive maintenance service for modern data centers and AI factories

    Vertiv™ Next Predict is a new service...
  • Vertiv expands flexible, energy-efficient edge cooling system for small, medium and edge applications in EMEA

    The Vertiv perimeter cooling system...

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • abstract
  • Abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP