Connect with us

Technology

Malicious Play Store apps put 8 million Android users at risk

Published

on

Malicious Play Store apps put 8 million Android users at risk

Malicious apps are pretty common, and it’s easy to accidentally download them if you’re not cautious. You’ll often find these apps on third-party app stores, shady websites, or through suspicious emails and texts. What you wouldn’t expect is to encounter them on the Google Play Store if you’re an Android user or the App Store if you’re on iPhone. 

While Apple does a great job of keeping its app marketplace safe, Google doesn’t quite measure up.

A new report has revealed that over a dozen malicious apps containing SpyLoan malware have been available on the Play Store. These apps have been downloaded by 8 million Android users, putting them at risk of extortion, harassment and financial loss. Below are images of four of the SpyLoan apps found on Google Play.

GET SECURITY ALERTS, EXPERT TIPS – SIGN UP FOR KURT’S NEWSLETTER – THE CYBERGUY REPORT HERE

Images of four of the SpyLoan apps found on Google Play (McAfee)

Advertisement

What is SpyLoan malware?

SpyLoan is malware often hidden in apps that promise instant loans. These apps reel people in with offers of quick, hassle-free loans, boasting low rates and hardly any requirements. While they might look legit at first glance, their real goal is to gather as much personal info as they can. 

Once they have it, they use it to harass or pressure users into paying ridiculous interest rates. They also use shady tactics like countdown timers or “limited-time” offers to create a fake sense of urgency, pushing people to act fast without thinking it through. Instead of helping with finances, these apps trap users in a cycle of debt and invade their privacy.

McAfee’s mobile research team has uncovered 15 apps on the Google Play Store packed with SpyLoan malware. These apps use the same code and systems, targeting users worldwide to steal data and send it to command-and-control (C2) servers. Many of them hide behind fake names and logos that mimic legitimate financial institutions, making them look trustworthy at first glance. You can find the names of these apps in the screenshot added below.

WHAT IS ARTIFICIAL INTELLIGENCE (AI)?

Fifteen apps on the Google Play Store packed with SpyLoan malware (McAfee)

Advertisement

McAfee, an App Defense Alliance partner tasked with helping keep the Play Store safe, reported the apps to Google. Google took action, and the malicious versions of the apps are no longer available on Google Play. 

We reached out to Google, and a rep confirmed that Android users are automatically protected against known versions of this malware by Google Play Protect. However, it is important to note that Google Play Protect may not be enough. Historically, it isn’t 100% foolproof at removing all known malware from Android devices.

ANDROID BANKING TROJAN EVOLVES TO EVADE DETECTION AND STRIKE GLOBALLY

How do these predatory apps work?

The goal of these malicious apps is to gather as much data as possible from infected devices, which they then use to extort users. Victims are often coerced into repaying loans at sky-high interest rates, with some even being threatened for delays. In extreme cases, the app operators have harassed victims’ families and sent death threats, using stolen personal photos as leverage.

These apps request intrusive permissions, giving them access to system data, cameras, call logs, contacts, location, and SMS messages. They justify this data collection by claiming it’s necessary for user verification and anti-fraud measures. 

Advertisement

Users signing up for these services are verified through a one-time password (OTP) to confirm their phone number is from the target region. They are also pressured to share additional details like ID documents, bank accounts, and employment information.

A woman holding an Android phone (Kurt “CyberGuy” Knutsson)

ANDROID BANKING TROJAN MASQUERADES AS GOOGLE PLAY TO STEAL YOUR DATA

4 ways to protect yourself from SpyLoan malware

1. Have strong antivirus software: Android has its own built-in malware protection called Play Protect, but the SpyLoan malware proves it’s not enough. Historically, Play Protect hasn’t been 100% foolproof at removing all known malware from Android phones. The best way to protect yourself from clicking malicious links that install malware that may get access to your private information is to have antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android and iOS devices.

Advertisement

2. Download apps from reliable sources: It’s important to download apps only from trusted sources like the Google Play Store. You might say I am contradicting myself, but the Play Store is still safer than other options out there. They have strict checks to prevent malware and other harmful software. However, even with the security measures provided by Google Play, downloading apps from the store does not guarantee 100% protection against malware or harmful software. Avoid downloading apps from unknown websites or unofficial stores, as they can pose a higher risk to your personal data and device. Never trust download links that you get through SMS.

3. Be cautious with app permissions: Always review the permissions requested by apps before installation. If an app requests access to features that seem unnecessary for its function, it could be a sign of malicious intent. Do not give any app Accessibility permissions unless you really need to. Avoid granting permissions that could compromise your personal data.

4. Take loans from legit institutions: Always take loans from legitimate financial institutions like banks or well-known lenders. Avoid sketchy apps or services promising instant cash with minimal requirements. They’re often too good to be true. Legit lenders are transparent about their terms, interest rates, and fees, and they won’t demand access to your personal data or pressure you with scare tactics. If you’re unsure about a lender, check reviews, verify their credentials, or consult a financial advisor before committing.

THE HIDDEN COSTS OF FREE APPS: YOUR PERSONAL INFORMATION

Kurt’s key takeaway

It can be tempting to use apps that promise instant loans, especially when you need the money. But they’re often just trying to scam you and push you into a never-ending debt cycle. If you need a loan, go to a trusted bank or lender. Protecting yourself from malicious apps like those infected with SpyLoan malware starts with staying informed and cautious. Always scrutinize the apps you download, stick to trusted platforms, and think twice before sharing sensitive information.

Advertisement

Do you think Google does enough to protect users from malware on the Play Store? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Advertisement

Answers to the most asked CyberGuy questions:

New from Kurt:

Copyright 2024 CyberGuy.com. All rights reserved.

Technology

Musk says he’s going to open-source the new X algorithm next week

Published

on

Musk says he’s going to open-source the new X algorithm next week

In 2023, what was then still called Twitter, open-sourced at least portions of the code that decided what it served up in your feed. But that GitHub repository is hopelessly out of date, with the vast majority of the files appearing to be from the initial upload three years ago. Elon Musk says that in seven days, he will open-source X’s new algorithm and finally give people a peek behind the curtain and possibly a technical explanation as to why your feed is 90 percent rage bait.

Elon has always made promises to open-source parts of X, and has followed through to at least some degree, including Grok-1 in 2024. But xAI is now on Grok-3, and the Grok GitHub repository hasn’t been updated in two years. The timing of the announcement open-sourcing the X algorithm is also likely to be met with some suspicion, as Musk is fending off criticism from across the globe and the political spectrum regarding Grok’s willingness to make deepfake nudes.

Musk says this release of the X algorithm will include “all code used to determine what organic and advertising posts are recommended to users.” He also says this will be just the first, with updates coming every four weeks, and that those will include developer notes highlighting any changes. Of course, considering how things played out in 2023, you’ll have to forgive us for taking that promise with a grain of salt.

Continue Reading

Technology

Covenant Health data breach affects nearly 500,000 patients

Published

on

Covenant Health data breach affects nearly 500,000 patients

NEWYou can now listen to Fox News articles!

When a healthcare data breach is first disclosed, the number of people affected is often far lower than the final tally. That figure frequently climbs as investigations continue. 

That’s exactly what happened with Andover, Massachusetts-based Covenant Health. The Catholic healthcare provider has confirmed a cyberattack discovered last May may have affected nearly 500,000 patients, a sharp increase from the fewer than 8,000 people it initially reported earlier this year. 

A ransomware group later claimed responsibility for the incident, though Covenant Health has not publicly confirmed the use of ransomware. The attackers accessed names, addresses, Social Security numbers and health information, among other sensitive data that could put patients at serious risk.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

UNIVERSITY OF PHOENIX DATA BREACH HITS 3.5M PEOPLE

Covenant Health detected suspicious activity in late May 2025, but investigators later confirmed attackers had already accessed systems days earlier. (Kurt “CyberGuy” Knutsson)

What happened in the Covenant Health breach

Covenant Health says it detected unusual activity in its IT environment May 26, 2025. A later investigation revealed that an attacker had actually gained access eight days earlier, on May 18, and was able to access patient data during that window.

In July, Covenant Health told regulators that the breach affected 7,864 individuals. After completing what it describes as extensive data analysis, the organization now says that up to 478,188 individuals may have been affected.

Covenant Health operates hospitals, nursing and rehabilitation centers, assisted living residences and elder care organizations across New England and parts of Pennsylvania. That wide footprint means the breach potentially touched patients across multiple states and care settings.

Advertisement

In late June, the Qilin ransomware group claimed responsibility for the attack, Bleeping Computer reported. The group alleged it stole 852 GB of data, totaling nearly 1.35 million files. Covenant Health has not confirmed those figures, but it did acknowledge that patient information was accessed.

According to the organization, the exposed data may have included names, addresses, dates of birth, medical record numbers, Social Security numbers, health insurance details and treatment information such as diagnoses, dates of treatment and types of care received.

700CREDIT DATA BREACH EXPOSES SSNS OF 5.8M CONSUMERS

Qilin ransomware lists Covenant Health on its data leak site. (Bleeping Computer)

What Covenant Health is telling patients

In a notice sent to regulators and patients, Covenant Health says it engaged third-party forensic specialists to investigate the incident and determine what data was involved. The organization says its data analysis is ongoing as it continues identifying individuals whose information may have been involved.

Advertisement

Then there are the familiar statements every company makes after a breach, claiming they’ve strengthened the security of their IT systems to help prevent similar incidents in the future. Covenant Health says it has also set up a dedicated toll-free call center to handle questions related to the breach.

Beginning Dec. 31, 2025, the organization started mailing notification letters to patients whose information may have been compromised. For individuals whose Social Security numbers may have been involved, Covenant Health is offering complimentary credit monitoring and identity theft protection services.

We reached out to Covenant Health, and the company confirmed the expanded scope of the incident and outlined steps being taken to notify patients and enhance security safeguards.

DATA BREACH EXPOSES 400K BANK CUSTOMERS’ INFO

The breach exposed highly sensitive information, including names, Social Security numbers, medical records and treatment details tied to nearly half a million patients. (Kurt “CyberGuy” Knutsson)

Advertisement

7 steps you can take to protect yourself after the Covenant Health breach

If you received a notice from Covenant Health, or if your data has been exposed in any healthcare breach, these steps can help reduce the risk of misuse.

1) Enroll in the free identity protection offered

If the organization offers you credit monitoring or identity protection, take it. These services can alert you to suspicious activity tied to your Social Security number, credit file or identity details before real damage is done. If you’re not offered one and want to be on the safer side, you might consider getting one yourself.

Identity theft companies can monitor personal information like your Social Security number, phone number and email address and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.

See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com

2) Monitor medical and insurance statements closely

Medical identity theft often shows up quietly. Review an explanation of benefits (EOBs), insurance claims and billing statements for services you don’t recognize. If something looks off, report it to your insurer immediately.

Advertisement

3) Place a fraud alert or credit freeze

A fraud alert tells lenders to take extra steps to verify your identity before approving credit. A credit freeze goes further by blocking new accounts entirely unless you lift it. If Social Security numbers were exposed, a freeze is usually the safer option.

To learn more about how to do this, go to Cyberguy.com and search “How to freeze your credit.” 

4) Use a password manager

Healthcare breaches often lead to credential-stuffing attacks elsewhere. A password manager ensures every account uses a unique password, so one exposed dataset can’t unlock everything else. It also makes it easier to update passwords quickly after a breach.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.

Advertisement

5) Be cautious of phishing scams and use strong antivirus software

Breaches are frequently followed by phishing emails, texts or calls that reference the incident to sound legitimate. Attackers may pose as the healthcare provider, an insurer or a credit bureau. Don’t click links or share information unless you verify the source independently.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

6) Consider a personal data removal service

Once your data leaks, it often spreads across data broker sites. Personal data removal services help reduce your digital footprint by requesting takedowns from these databases. While they can’t erase everything, they lower your exposure and make targeted fraud harder.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Advertisement

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

7) Review your credit reports regularly

You’re entitled to free credit reports from all major bureaus. Check them for unfamiliar accounts, hard inquiries or address changes. Catching fraud early makes it far easier to contain.

Kurt’s key takeaway

Healthcare organizations remain prime targets for cybercriminal groups because of the volume and sensitivity of the data they store. Medical records contain a mix of personal, financial and health information that is difficult to change once exposed. Unlike a password, you cannot reset a diagnosis or treatment history. This breach also shows how early disclosures often underestimate impact. Large healthcare networks rely on complex systems and third-party vendors, which can slow forensic analysis in the early stages. As investigations continue, the number of affected individuals often climbs.

Do you think healthcare organizations do enough to protect user data? Let us know by writing to us at Cyberguy.com.

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter. 

Copyright 2025 CyberGuy.com.  All rights reserved.

Continue Reading

Technology

Amazfit’s Active 2 tracker and Blu-rays are this week’s best deals

Published

on

Amazfit’s Active 2 tracker and Blu-rays are this week’s best deals

The start of the year is typically a great time to snag deals on health and fitness gear, including trackers and wireless earbuds, and this week was no exception. We found plenty on sale and highlighted the best picks below. Not all of the deals are related to New Year’s resolutions, though; there are also a number of other worthwhile deals worth checking out. Despite the Consumer Electronics Show wrapping up earlier this week, we’re already seeing deals roll in, for example. And if your main goal is to unwind this weekend, we’ve spotted solid deals on Blu-rays to help you relax. Below, you’ll find all of our favorite deals from this week.

Of fitness trackers on sale right now, the deal on the Amazfit Active 2 is ideal, especially if you’re on a budget. It’s currently on sale for just $84.99 ($15 off) at Amazon, Best Buy, and Target, which is just $5 shy of its lowest price to date.

​​We think the Active 2 is one of the best fitness tracker you can currently buy, namely because it offers a feature set you don’t typically don’t find at this price point. It covers most of the health and fitness features people need and then some, with continuous heart rate and blood oxygen tracking, in addition to menstrual cycle tracking. You also get offline maps with turn-by-turn navigation and up to nine days of battery life — far longer than most smartwatches. It looks stylish, too, thanks to its stainless steel case and 2,000-nit OLED display that makes it seem more expensive than it is.

What makes the latest Nano Charger stand out from previous models its built-in display, which shows real-time charging details like power flow, charge level, and temperature at a glance. If you have an iPhone 15 or newer — or an iPad Pro released in 2020 or later — it can also adjust charging based on the device’s power needs. What’s more, it delivers up to 45W of power in a compact design with folding prongs that rotate 180 degrees, allowing you to squeeze it into smaller spaces.

Three more of this week’s best deals

Advertisement
Continue Reading

Trending