Security Breach: Gooligan Malware Campaign

Security researchers from Checkpoint Software Technologies have discovered a new alarming malware campaign named Gooligan. With this campaign, more than a million Android devices were infected, resulting in the breach of over a million Google accounts, with the number increasing by an average of 13,000 new breached devices each day.

Check Point’s Security Team first encountered Gooligan’s code in the malicious SnapPea app last year, in August 2016. About 60% of these devices belong to the Asia region, followed by the Americas with 19%, and about 15% are in Africa. The Checkpoint team is working with Google to investigate the source of Gooligan.

How it infects

Gooligan spreads through legitimate-looking apps hosted on third-party Android app stores (other than the Google Play Store). The infected application is installed through phishing campaigns, and application links are also shared using SMS and other communication services.

How Gooligan works

Once the infected application is installed on the phone, it automatically connects with the Gooligan command & control servers (C&C). It then downloads a rootkit that takes advantage of multiple Android 4 and 5 exploits, some of which are VROOT (CVE-2013-6282) and Towelroot (CVE-2014-3153). These exploits are more than two years old but are still able to exploit Android phones because users fail to update their phones with the latest security fixes and patches.

Once the exploits run successfully, the attacker has full access to the Android phone and can execute privileged commands remotely. After that, Gooligan downloads a new module from the C&C server and installs it onto the infected device. This module takes over Google Play Services to mimic user behavior so it goes undetected. This allows Gooligan to:

  • Steal a user’s Google email account and authentication token information
  • Install apps from Google Play and rate them to raise their reputation
  • Install adware to generate revenue
  • Use the infected phone to install apps and adware which generate revenue for the attacker
  • Leave a positive review with a high rating on the Google Play Store for apps it remotely installed on the phone

How to check if your Google Account is breached

  • Checkpoint, with the help of Google, created a database of compromised email addresses, so you can check if your account is compromised.
  • If your account is breached, follow the instructions provided.
  • Firstly, change your Google Account password.
  • Re-install the Android operating system using the flashing technique.

Takeaways from this breach

This is the biggest account breach in Google’s history.

  • Update your phone with the latest security patches.
  • Never install an application from untrusted sources.

References

  • Check Point Research — 1 Million Google Accounts Breached by Gooligan

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.