Loan applications designed to exploit users have emerged as a significant threat, as new malware continues to surface despite the crackdown efforts by companies like Google. A recent report from a security firm reveals that 15 applications have been identified as hosting ‘SpyLoan,’ a potentially unwanted program (PUP) that has expanded its reach since its inception in 2020. While Google has paused some of the implicated applications, individuals who have downloaded them will need to uninstall them manually.
Fifteen SpyLoan Applications Discovered on Android Devices
The mobile research team at McAfee found 15 SpyLoan applications available on the Play Store, targeting users of Android smartphones. These applications have reportedly been downloaded to over 8 million devices, according to findings by the security firm. Some of the applications were either suspended or updated following the publication of this report.
Examples of SpyLoan applications found on the Play Store
Photo Credit: McAfee
Once installed, these SpyLoan apps typically request extensive permissions and begin harvesting considerable amounts of personal data from users’ smartphones. This information is encrypted before being sent to a command-and-control server. According to McAfee, these applications share a unified framework and coding structure, offering a similar user experience—including the request for a one-time password (OTP).
Despite imitating well-known app logos and names, these SpyLoan applications have ingeniously circumvented the screening processes Google implements to filter apps on its Play Store. They entice users with promises of fast and hassle-free loans, often employing a countdown timer to nudge individuals towards quick sign-ups.
User feedback on the Play Store reveals numerous one-star ratings, with complaints regarding alarming phone calls and messages from recovery agents. Many of these users also report threats involving doctored images obtained from their devices.
Users are urged to take immediate action with fabricated countdowns
Photo Credit: McAfee
McAfee’s research indicates that India is at the forefront of the prevalence of fake loan apps in the third quarter of 2024, followed by Mexico, the Philippines, Indonesia, Thailand, Kenya, Colombia, Vietnam, Chile, and Nigeria in terms of affected users.
In India, the Reserve Bank of India (RBI) and the Ministry of Finance have previously taken measures against numerous apps over recent years. However, McAfee has observed an ongoing increase in the number of such applications, despite various government interventions.
Citizens are encouraged to inspect their smartphones for any of the following applications. If any of these are present, users must uninstall them manually to prevent unauthorized access to their personal information. It is also advisable for users to limit app installations to those from reputable sources to reduce exposure to these risky applications.
App Name | Package | Downloads | Country |
---|---|---|---|
Préstamo Seguro-Rápido, seguro | com.prestamoseguro.ss | 1M | Mexico |
Préstamo Rápido-Credit Easy | com.voscp.rapido | 1M | Colombia |
ได้บาทง่ายๆ-สินเชื่อด่วน | com.uang.belanja | 1M | Senegal |
RupiahKilat-Dana cair | com.rupiahkilat.best | 1M | Senegal |
ยืมอย่างมีความสุข – เงินกู้ | com.gotoloan.cash | 1M | Thailand |
เงินมีความสุข – สินเชื่อด่วน | com.hm.happy.money | 1M | Thailand |
KreditKu-Uang Online | com.kreditku.kuindo | 500K | Indonesia |
Dana Kilat-Pinjaman kecil | com.winner.rupiahcl | 500K | Indonesia |
Cash Loan-Vay tiền | com.vay.cashloan.cash | 100K | Vietnam |
RapidFinance | com.restrict.bright.cowboy | 100K | Tanzania |
PrêtPourVous | com.credit.orange.enespeces.mtn.ouest.wave.argent.tresor.payer.pret | 100K | Senegal |
Huayna Money – Préstamo Rápido | com.huaynamoney.prestamos.creditos.peru.loan.credit | 100K | Peru |
IPréstamos: Rápido Crédito | com.credito.iprestamos.dinero.en.linea.chile | 100K | Chile |
ConseguirSol-Dinero Rápido | com.conseguir.sol.pe | 100K | Peru |
ÉcoPrêt Prêt En Ligne | com.pret.loan.ligne.personnel | 50K | Thailand |