Gooligan is Android malware known for stealing authentication tokens associated with Google services, enabling unauthorized access to data across multiple Google applications. Its documented behavior centers on post-compromise collection of locally accessible account artifacts rather than destructive activity. By targeting authentication tokens, Gooligan supports session abuse and downstream access to cloud-linked user data without necessarily requiring direct password theft. The malware is associated with Android device compromise and is relevant to mobile-focused credential and account-access operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Gooligan steals authentication tokens that can be used to access data from multiple Google applications.
Gooligan steals authentication tokens that can be used to access data from multiple Google applications. RCSAndroid can collect passwords for Wi-Fi networks and online accounts, including Skype, Facebook, Twitter, Google, WhatsApp, Mail, and LinkedIn. Monokle can retrieve the salt used when storing the user’s password, aiding an adversary in computing the user’s plaintext password/PIN from the stored password hash.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware that steals authentication tokens to access Google application data.
Android malware that steals authentication tokens for access to Google application data.
Android malware that steals Google authentication tokens to access user data across Google apps.
Android malware that steals Google authentication tokens to access user data across Google apps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.