Skip to main content

‘Gooligan’ Android malware affects more than 1 million Google accounts

history of malware android
Image used with permission by copyright holder
Android smartphone manufacturers aren’t the best at updating smartphones to the latest software from Google — that means older devices are more susceptible to attacks thanks to public vulnerabilities that haven’t been patched. Chances are your Android phone is running an older version and unfortunately, there is a malware campaign affecting more than 1 million Google accounts.

Security firm Check Point released information about malware dubbed “Gooligan,” which can steal your Gmail account and authentication information, install apps from Google Play, rate them without your consent, and install adware. The latter two is used to improve app store ratings and “generate revenue.”

The malware only infects devices when a user downloads and installs a “Gooligan-infected app” on a vulnerable Android device via a third-party app store or from malicious links — you’re fine if you only download from the Google Play Store and are using a newer Android device running Android 6.0 or higher.

“After an infected app is installed, it sends data about the device to the campaign’s Command and Control (C&C) server,” the research team writes in a blog post. “Gooligan then downloads a rootkit from the C&C server that takes advantage of multiple Android 4 and 5 exploits … These exploits still plague many devices today because security patches that fix them may not be available for some versions of Android, or the patches were never installed by the user. If rooting is successful, the attacker has full control of the device and can execute privileged commands remotely.”

Unfortunately, nearly 74 percent Android devices run Android 4.2 Jellybean, Android 4.4 KitKat, and Android 5.0 Lollipop.

Adrian Ludwig, director of Android security at Google, said his team has been tracking a family of malware called “Ghost Push” since 2014. Ghost Push is a collection of potentially harmful apps (PHAs) that are the “most often downloaded outside of Google Play.”

“After they are installed, Ghost Push apps try to download other apps. For over two years, we’ve used Verify Apps to notify users before they install one of these PHAs and let them know if they’ve been affected by this family of malware.”

Verify Apps is an Android feature that scans devices for security threats and Google said it found more than 40,000 apps associated with the malware in 2015. Now, the company says Android detects and prevents installations of more than 150,000 variants of Ghost Push. Gooligan is one such variant of Ghost Push and Ludwig said his team has “worked closely” with Check Point to protect users.

As the motivation for Ghost Push apps is to promote apps and generate revenue, Ludwig says Google has found no evidence that user data has been accessed. There is also no evidence that a specific group of users or businesses were targeted. Google says it has improved the Verify Apps feature to protect users from these apps in the future — even if you try to install an infected app, your device will notify you and stop the installation. The search giant is also continually removing apps associated with the Ghost Push family on Google Play, as well as apps that have “benefitted from installs delivered by Ghost Push to reduce the incentive for this type of abuse.”

Google urges users to download apps from the Google Play Store so as to reduce the threat of installing a malicious app. For those accounts that have been compromised, Google has contacted users and revoked authentication tokens so that they can securely sign back in.

If you’re worried your account may be compromised, Check Point has a handy tool that lets you check. Just type in your email and hit “check” and the website will tell you if your account is safe or not.

Editors' Recommendations

Julian Chokkattu
Former Digital Trends Contributor
Julian is the mobile and wearables editor at Digital Trends, covering smartphones, fitness trackers, smartwatches, and more…
Android phones finally have their own version of AirTags
Renders of Chipolo's new Point trackers that work with Google's Find My Device network.

Google's new Find My Device tracking service will soon launch with an important third-party provider. Chipolo has announced two new trackers for the service: the Chipolo One Point item tracker and the Chipolo Card Point wallet finder.

By offering these trackers, Chipolo will be among the first companies in the market to provide trackers that work with Google's new tracking network. Google announced its new Find My Device network last year. In short, it's Google's answer to Apple's Find My network. Find My Device can use other nearby Android devices to track your lost phone, item tracker, etc. — just like how Find My uses iPhones and other Apple devices to locate lost iPhones and AirTags.

Read more
The 1Password Android app just got a huge upgrade
The 1Password Android app, side-by-side, showing the light and dark mode.

The 1Password password manager app for Android has just gotten a huge new update, which unlocks the use of passkeys through its app. Held by many as the future of secure authentication, passkeys are the next evolution of the password, and from today, you'll be able to use 1Password to create, manage, and unlock your accounts that use passkey authentication.

1Password is one of the world's most popular password managers, with over 700,000 passwords saved. But it clearly sees that the future is elsewhere, as it has been leading the charge on taking passkeys into the mainstream.

Read more
Google just announced 8 big Android updates. Here’s what’s new
A photo of many Android figurines on a white wall.

At Moblie World Congress (MWC ) 2024, Google is bringing a healthy bunch of new features to Android. In line with the AI push all across the industry, some notable AI-driven enhancements are on the table. There are also a handful of core Android features that sound practically amazing.
The first in line is Gemini. The generative AI chatbot recently got a standalone app for Android, and now it’s headed for the Google Messages app. Users can chat with Gemini directly in the messaging app and use its generative capabilities for a host of things, like drafting replies, refining a message, and more.

Another feature that was showcased a while ago is finally ready for prime time. Android Auto is gaining support for message summarization for standalone texts and group chats, and it can also suggest replies. With a single tap, users will also be able to drop a message, start a call, and share an estimated arrival time. The idea is to deploy AI for crucial tasks so that it can minimize distractions while driving.
Lookout, an accessibility-centric feature for users with vision challenges, is also getting meaningful AI love. On Android phones, Lookout will now read AI-generated captions and descriptions for media content. For now, the AI boost to Lookout and Messages is limited to the English language.

Read more