A brand new set of 15 SpyLoan apps with over 8 million installs was found on Google Play, focusing on primarily customers from South America, Southeast Asia, and Africa.
The apps have been found by McAfee, a member of the ‘App Protection Alliance,’ and have now been faraway from Android’s official app retailer.
Nevertheless, their presence on Google Play is indicative of the menace actors’ persistence, as even latest regulation enforcement actions in opposition to SpyLoan operators haven’t curbed the difficulty, says McAfee.
The final main “SpyLoan cleanup” on Google Play was in December 2023, when over a dozen apps that had amassed 12 million downloads have been eliminated.
SpyLoan modus operandi
SpyLoan apps are instruments promoted as monetary instruments that supply customers loans by way of a fast-track approval course of underneath misleading and infrequently false phrases.
As soon as the victims set up these apps, they’re validated through a one-time password (OTP) to make sure they’re primarily based within the goal area. Then they’re requested to submit delicate identification paperwork, worker info, and banking account information.
Moreover, the apps misuse their permissions on the machine to gather in depth delicate information, together with entry to the consumer’s contact lists, SMS, digital camera, name log, and placement, to make use of within the extortion course of.
McAfee notes that the aggressive data-gathering ways of those apps prolong to exfiltrating all SMS messages on the sufferer’s machine, in addition to GPS/community location, machine info, OS particulars, and sensor information.

Supply: McAfee
As soon as a consumer will get a mortgage by way of the app, they’re certain to high-interest funds, and often harassed and blackmailed by the operators utilizing the info stolen from their telephones. In some instances, the scammers name members of the family of the loanee, harassing them as nicely.
8 million downloads on Google Play
McAfee’s investigation recognized 15 malicious SpyLoan apps, which have been put in over 8 million instances by way of the Play Retailer alone. Beneath is a listing of the eight hottest:
- Préstamo Seguro-Rápido, Seguro – 1,000,000 downloads, primarily targets Mexico
- Préstamo Rápido-Credit score Simple – 1,000,000 downloads, primarily targets Colombia
- ได้บาทง่ายๆ-สินเชื่อด่วน – 1,000,000 downloads, primarily targets Senegal
- RupiahKilat-Dana cair – 1,000,000 downloads, primarily targets Senegal
- ยืมอย่างมีความสุข – เงินกู้ – 1,000,000 downloads, primarily targets Thailand
- เงินมีความสุข – สินเชื่อด่วน – 1,000,000 downloads, primarily targets Thailand
- KreditKu-Uang On-line – 500,000 downloads, primarily targets Indonesia
- Dana Kilat-Pinjaman kecil – 500,000 downloads, primarily targets Indonesia

Supply: McAfee
Regardless of Google’s app overview mechanisms to dam software program that violates the Play Retailer’s phrases, SpyLoan apps proceed to slip by way of the cracks.
To guard in opposition to this danger, learn consumer evaluations, examine the developer’s status, restrict the permissions granted to apps upon set up, and ensure Google Play Defend is lively on the machine.