GPlayed Android Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
GPlayed is delivered either as a direct download on an already compromised device or disguised as a legitimate application through the Google Play Store.
Once installed, GPlayed will connect to a command and control server before disguising itself as "Google Play Marketplace" and asking the user for full permissions. GPlayed has extensive native capabilities, including:
- Collection of user and contact information.
- Making calls and sending SMS messages.
- Injecting JavaScript code.
- Exfiltrate payment information and banking credentials
- Resetting and locking the device.
GPlayed also has the ability to load new modules to add extra features, although at present none have been observed in the wild.
Remediation advice
To prevent and detect a trojan infection, ensure that:Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:44 pm