SpyLend Android malware downloaded 100,000 times from Google Play

SpyLend Android malware downloaded 100,000 times from Google Play
Summary: A malicious Android app named SpyLend has been downloaded over 100,000 times from Google Play, masquerading as a financial tool but ultimately acting as a predatory loan app targeting users in India. The app, along with others in its category, requests excessive data permissions, leading to data theft used for blackmail and extortion. Despite its removal from Google Play, it may still be active on users’ devices, collecting sensitive information.

Affected: Android users in India

Keypoints :

  • The SpyLend app is part of a group of malicious applications called “SpyLoan,” which deceive users by claiming to offer financial services while stealing personal data.
  • Stolen data includes contacts, messages, photos, location, and even banking details, which can be used for extortion or sold to cybercriminals.
  • The app specifically targets Indian users by altering its interface based on location and misleadingly claims to be a registered Non-Banking Financial Company (NBFC).

Source: https://www.bleepingcomputer.com/news/security/spylend-android-malware-downloaded-100-000-times-from-google-play/