GPlayed is an Android malware family that masquerades as a Google Play-related application and combines surveillance, phishing, SMS abuse, and destructive device actions. It has been observed using the Play Store icon and the name "Google Play Marketplace" to appear legitimate to victims.
GPlayed supports persistence by registering for Android boot events so it can automatically start after device reboot. For command and control, it communicates over standard application-layer protocols using HTTP requests, with WebSockets available as a fallback channel.
Its collection capabilities include harvesting installed application lists, browser cookies, contact lists, SMS messages, and device profiling data such as IMEI, phone number, and country. It can also send SMS messages from the compromised device, enabling fraud or operator-controlled messaging activity.
GPlayed includes phishing functionality through a deceptive WebView that impersonates a Google service to solicit and steal payment card information. In addition to espionage and fraud-oriented features, it also has destructive capability and can wipe the device.
Overall, GPlayed is a multifunctional Android threat that blends impersonation of trusted Google branding with persistence, data theft, phishing, command-and-control resilience, and impact operations on infected mobile devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
BRATA can use both HTTP and WebSockets to communicate with the C2 server. GPlayed has communicated with the C2 using HTTP requests or WebSockets as a backup. LightSpy has used both HTTPS and Websockets to communicate with the C2. | AbstractEmu can use HTTP to communicate with the C2 server; AhRat can communicate with the C2 using HTTPS requests; Android/AdDisplay.Ashas has communicated with the C2 server using HTTP; Android/Chuli.A used HTTP uploads to a URL as a command and control mechanism; Asacub has communicated with the C2 using HTTP POST requests; BOULDSPY uses unencrypted HTTP traffic between the victim and C2 infrastructure; BRATA can use both HTTP and WebSockets to communicate with the C2 server; Bread communicates with the C2 server using HTTP requests; PROMETHIUM used StrongPity to communicate with the C2 server using HTTPS; Cerberus communicates with the C2 server using HTTP; Chameleon can use HTTP to communicate with the C2 server; CHEMISTGAMES has used HTTPS for C2 communication; Concipit1248 communicates with the C2 server using HTTP requests; Corona Updates communicates with the C2 server using HTTP requests; Dark Caracal controls implants using standard HTTP communication; EventBot communicates with the C2 using HTTP requests; Exobot has used HTTPS for C2 communication; Exodus One checks in with the command and control server using HTTP POST requests; FluBot can use HTTP POST requests on port 80 for communicating with its C2 server; FlyTrap can use HTTP to communicate with the C2 server; Golden Cup has communicated with the C2 using MQTT and HTTP; GoldenEagle has used HTTP POST requests for C2; GPlayed has communicated with the C2 using HTTP requests or WebSockets as a backup; Gustuff communicates with the command and control server using HTTP requests; Hornbill can use HTTP and HTTP POST to communicate information to the C2; INSOMNIA communicates with the C2 server using HTTPS requests; LightSpy has used both HTTPS and Websockets to communicate with the C2; Red Alert 2.0 has communicated with the C2 using HTTP; RedDrop uses HTTP requests for C2 communication; Riltok communicates with the command and control server using HTTP requests; Rotexy can communicate with the command and control server using JSON payloads sent in HTTP POST request bodies; RuMMS uses HTTP for command and control; SharkBot can use HTTP to send C2 messages to infected devices; SilkBean has used HTTPS for C2 communication; Skygofree can be controlled via HTTP; SpyC23 can communicate with the Command and Control server using HTTPS; TrickMo communicates with the C2 by sending JSON objects over unencrypted HTTP requests; ViceLeaker uses HTTP requests for C2 communication; YiSpecter has connected to the C2 server via HTTP.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android trojan that impersonates Google Play branding to appear legitimate.
Android trojan that reads SMS messages from infected devices.
Android trojan capable of sending SMS messages.
Android trojan that presents phishing WebViews impersonating Google services to steal credit card information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.