SPYLEND: The Android App Available on Google Play Store: Enabling Financial Cyber Crime & Extortion

Feb. 24, 2025, 9:08 a.m.

Description

A sophisticated Android malware called SpyLend, disguised as a 'Finance Simplified' app, is targeting Indian users through the Google Play Store. The app leverages location-based targeting to display unauthorized loan applications, enabling predatory lending, blackmail, and extortion. It has rapidly gained downloads, increasing from 50,000 to 100,000 in a week. The malware collects sensitive user data, including photos, contacts, and clipboard content, which is then used for harassment and extortion. The app's infrastructure suggests Chinese-speaking attackers are behind the operation. It employs various techniques to evade detection and persist on devices, posing a significant threat to user privacy and financial security.

Date

  • Created: Feb. 22, 2025, 9:46 p.m.
  • Published: Feb. 22, 2025, 9:46 p.m.
  • Modified: Feb. 24, 2025, 9:08 a.m.

Attack Patterns

  • SpyLend

Additional Informations

  • Finance
  • British Indian Ocean Territory
  • India