More Than 1 Million Google Accounts Breached By Hackers' Android Malware

By Precious Gem de Peralta
Android 4.0
Check Point discovered that hackers are exploiting the security vulnerabilities in Android versions 4 (Jelly Bean, Kit Kat) and 5 (Lollipop) with a new variant of Android malware called Gooligan. Alison Chaiken via Flickr

An app-installing malware has breached more than 1 million Google accounts and infected Android devices. Security firm Check Point has revealed that the malware campaign called "Gooligan" has been compromising 13,000 devices per day.

Check Point discovered that hackers are exploiting the security vulnerabilities in Android versions 4 (Jelly Bean, Kit Kat) and 5 (Lollipop). The firm went as far as to dub it as the "biggest theft of Google accounts". Apparently, the stolen "authentication tokens" are being used by the cyber criminals to access data in the person's account that include Google Play, Gmail, Google Photos, Google Docs, G Suite and Google Drive.

Though the extent of the malware's damage has been discovered, this new variant of Android malware had already been found by Check Point last year in the SnapPea app. The firm assured that they are working "closely with the Google to investigate the source of the Gooligan campaign". Once the affected app has been installed, the malware "collects data about the devices and downloads rootkits". Google pointed out that it does not actually "access any personal emails of files".

According to Forbes, users are forced to download apps "as part of a huge advertising fraud scheme". The ones responsible for this are "making as much as $320,000 a month". It's being used to "boost and app's ranking" and get a huge profit from it. Among the fake apps infected by Gooligan are WiFi Enhancer, WiFi Master, Memory Booster, Clean Master, YouTube Downloader, Slots Mania, Talking Tom 3 and the evidently malicious Sex Photo, PornClub and So Hot.

The above-mentioned versions of Android mobile operating system amount to 74 percent of Android devices currently being used. 40 percent of the Google accounts breached are in Asia, 19 percent in the Americas, 15 percent in Africa and 9 percent in Europe.

Possible victims of the breach can check their Google accounts if it has been compromised by going to gooligan.checkpoint.com. Owners who have infected devices are advised to power off their gadgets. They should bring it to a certified technician or mobile service provider. The Android device has to undergo a "clean installing of an operating system". Once the device has been successfully "re-flashed", the Google account password has to be changed.

According to The Verge, this is not the first time that cybercriminals have used such malware to improve certain apps' ranking and generate revenue from it. Google had removed a "family of apps called Brain Test" last year. Though the tech company actually scans for harmful apps in the Play Store, there are still instances where some of them cannot be detected.

  • [Exclusive Interview] A revelation within the brink of life and death — Meg Leung’s mission in Christian art

    Meg Leung (梁麗橋), an artist with a lifelong love for watercolor painting, sees her art as more than a means of expressing her inner world; it is a bridge connecting her to God. Her artistic journey has revealed God’s perfect plan and inspired her to communicate the power of faith through her wor

  • Transgenderism a fundamental human right? Hong Kong public disagrees, survey finds

    A 2024 survey from the Society for Truth and Light (明光社)'s Center for Life and Ethics Research reveals that respondents from various backgrounds prioritize personal safety and fairness when it comes to transgender issues. When laws involve moral judgments, most respondents believe courts should not make the decisions. The study also indicates that religious believers share similar views with non-religious respondents, reflecting that many churches may rarely address gender topics in depth.

  • Discipleship and Evangelism: Walking the Path of the Great Commission

    Like an ever-flowing spring, the gospel refreshes dry, parched lands and needs our unwavering passion and steadfast faith to transform lives and bring renewal. The "flame in our hearts" calls Christians to keep their faith and love for the Lord ablaze, representing the work and power of the Holy Spirit, driving us to proclaim God's glory boldly.

  • North America Chinese Evangelical Seminary year-end report highlights significant ministry progress

    As the year draws to a close, Rev. James Liu, President of the Chinese Evangelical Seminary North America (CESNA), reflected on the seminary’s remarkable growth and ministry development over the past year. Dedicated to providing theological education to Chinese Christians, CESNA continues to uphold its mission to remain faithful to the gospel and nurture believers. This year’s achievements span academic, ministerial, and outreach endeavors, fostering spiritual growth and advancing missionary wo