SpyLoan
SpyLoan is an Android malware/riskware family embedded in predatory loan applications, including apps distributed through Google Play, that masquerade as quick-loan or low-friction lending services. It has been active since at least 2020 and has been described as a repeat offender. The apps use social engineering to lure users with promises such as fast cash, low-interest loans, and minimal checks, and in some cases were also promoted via Facebook posts. Once installed, SpyLoan apps request intrusive permissions and harvest extensive victim data, including contacts, SMS messages, call logs, device identifiers and system information, coarse location, camera access, identification documents, bank account details, employment information, and personal photos. Reported behavior includes validating victims with one-time-password checks tied to targeted regions and exfiltrating stolen data to command-and-control servers, with some reporting noting AES-128 encryption and shared exfiltration/C2 frameworks across samples. The stolen information is used for harassment, extortion, inflated repayment demands, identity abuse, and surveillance. Reported targets span users in Latin America, Africa, and Asia, including Mexico, Colombia, Senegal, Thailand, Indonesia, Vietnam, Tanzania, Peru, and Chile. Multiple reports tie SpyLoan to surveillance, extortion, and identity theft, and Kaspersky classified it among frequently seen Android RiskTool apps while Zscaler identified it as a major driver of a year-over-year rise in Android spyware activity. Check Point also reported SpyLoan extortion malware in a Google Play app named RapiPlata. McAfee documented 15 SpyLoan-infected Android apps on Google Play with more than 8 million combined downloads, and ESET previously reported another set of 18 SpyLoan apps stealing personal and financial data. Shared code and infrastructure suggest either a common developer or a reusable criminal framework used by multiple operators.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
2 techniques
Execution
Credential Access
2 techniques
Credential Access
The end goal of the financial scheme is to collect as much information as possible from infected devices, which could then be used to extort users by coercing them into paying the loans back at higher interest rates, and in some cases, for delayed payments or intimidating them with stolen personal photos.
Collection
1 technique
Collection
The end goal of the financial scheme is to collect as much information as possible from infected devices, which could then be used to extort users by coercing them into paying the loans back at higher interest rates, and in some cases, for delayed payments or intimidating them with stolen personal photos.
IOCs tracked for this family
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RiskTool family prominently encountered among mobile users in the quarter.
A predatory finance app that uses social engineering to lure users, then steals contacts, messages, and device identifiers for harassment, extortion, or identity abuse.
Android spyware family associated with surveillance, extortion, and identity theft activity.
Extortion malware distributed via a Google Play app (RapiPlata).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.