SpyLoan Malware Apps Used to Blackmail, Extort Users Using Personal Data Detected on Play Store

These predatory apps were downloaded over 12 million times over several months, before Google removed 17 of the 18 offending applications.

Advertisement
Written by David Delima, Edited by Siddharth Suvarna | Updated: 6 December 2023 17:13 IST
Highlights
  • SpyLoan apps are being used to extort borrowers into repaying loans
  • These apps collect vast amounts of data to steal user data
  • Google has removed most of the apps being used to target Android users

Google has removed 17 out of the 18 SpyLoan apps from the Play Store

Photo Credit: Pixabay/ @neotam

Android smartphones are at risk of malicious loan apps that were downloaded several million times from the Google Play store, according to details shared by security researchers. As many as 18 apps identified as 'SpyLoan' malware were spotted on the store over the course of this year. These predatory lending apps are designed to collect vast amounts of information from a user's device when they borrow money— these are later used to blackmail and extort them into repaying the sum with high interest amounts.

ESET researchers have revealed details of the apps used by loan sharks to deceive users and the various methods used to bypass some of the restrictions put in place on the Play Store. The malware is typically designed with attractive user interfaces and advertise easy and quick access to funds, with high-interest repayment terms. The apps reportedly target users living in Africa, Latin America, and Southeast Asia.

In addition to completing the required documentation and Know Your Customer (KYC) identification required to publish their apps on the Play Store, these SpyLoan apps are also designed to show (or link to) official-looking websites that contain fake information with details and photos of employees sourced from stock image websites.

Advertisement

While the loaned amount is disbursed to users, these predatory loan apps ask users to share different kinds of sensitive information by granting different permissions on their phone, including access to the camera, contacts, messages, and call-logs, images, Wi-Fi network details, calendar information and other personal information. These are then exfiltrated to the servers of the loan sharks.

Advertisement

Instead of providing users with enough time to repay the loaned amount, the SpyLoan apps will reduce the amount of time before a user can repay the amount to a few days — in clear violation of Google's Financial Services policy that a loan tenure cannot be set for less than 60 days. One of the reviews left by users states that they had to repay 450 pesos (roughly Rs. 2,160) with an interest of 549 pesos (roughly Rs. 2,640) — paying a total of 999 pesos (roughly Rs. 4,800).

SpyLoan apps attempting to access a user's personal information
Photo Credit: Screenshot/ ESET

Advertisement

 

In order to push users to repay the short term, high interest rate loans, the apps use the data exfiltrated from their phones to blackmail them into repaying the loaned amount with a high rate of interest.

Advertisement

ESET says that out of the 18 apps it previously disclosed to Google, the search giant removed 17 apps. The last app is still available on the app store as a new version of the app was published to the Play Store and it does not offer the same functionality or feature the same permissions.

The list of apps detected by ESET include 4S Cash, AA Kredit, Amor Cash, Cartera grande, Cashwow, CrediBus, EasyCash, EasyCredit, Finupp Lending, FlashLoan, Go Crédito, GuayabaCash, Instantáneo Préstamo, Préstamos De Crédito-YumiCash, PréstamosCrédito, Rápido Crédito, TrueNaira.

While these apps have been removed from the Play Store, they will remain on the devices of users who have these apps installed until they manually remove them. If you have any of these apps installed on your smartphone, you should uninstall them right away.


Is the Samsung Galaxy Z Flip 5 the best foldable phone you can buy in India right now? We discuss the company's new clamshell-style foldable handset on the latest episode of Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Nothing Phone 3a Lite Launched With Glyph Light At This Price
  2. Oppo Find X9 Series Confirmed to Be Available in India via Flipkart
  3. Amazon Fire TV Stick 4K Select Launched in India With Vega OS
  4. TRAI, DoT Approve Presentation of Caller Names During Incoming Calls
  5. Moto G67 Power 5G India Launch Date, Key Features Announced
  6. Vivo X300 Series Price, Key Features Leaked Ahead of Global Launch
  7. Oppo Find X9 Series With Hasselblad-Tuned Cameras Launched Globally
  8. Bad Girl OTT Release Date: When and Where to Watch it Online?
  9. Nothing Phone 3a Lite Launch Today: Everything You Need to Know
  10. US Senators Want to Ban Teenagers From Using AI Chatbots
  1. Idli Kadai, Starring Dhanush, Now Streaming on Netflix: What You Need to Know
  2. Ideabaaz Now Streaming on ZEE5: Everything You Need to Know
  3. Grey’s Anatomy Season 22 OTT Release: Know Where to Watch it Online?
  4. Bad Girl OTT Release Date: When and Where to Watch Tamil Drama Online?
  5. Adobe Partners With Google Cloud to Integrate Frontier AI Models Across Its Platforms
  6. Vivo X300, Vivo X300 Pro Price and Key Specifications Leaked Ahead of Global Launch
  7. OnePlus 15 India Launch Date Announced; to Debut as First Snapdragon 8 Elite Gen 5 Phone in India
  8. Rangbaaz: The Bihar Chapter OTT Release Date: When and Where to Watch Crime Thriller Movie Online?
  9. French Lawmakers to Review Proposal to Ban CBDC, Support Bitcoin Reserve and Crypto Oversight
  10. Nothing Phone 3a Lite Launched With Essential Key, Glyph Light and 5,000mAh Battery: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.