Nasty Trojan Infects Over a Million Android Phones

A nasty strain of Android malware that has been in the wild for the last two years is once again rearing its ugly head. Gooligan, the name given to malware that has been found in at least 86 malicious apps, has been infecting Android handsets at a rate of 13,000 devices worldwide per day, Israeli security firm Check Point Software said in a blog posting today (Nov. 30).

The apps were downloaded from unauthorized, third-party app stores. So if you're not sticking to Google Play for downloads, you should be.

According to Check Point, the apps in question include StopWatch, Perfect Cleaner, and WiFi Enhancer, all of which are available in third-party marketplaces. They exploit known flaws in older Android distributions, including 4.1-4.3 Jelly Bean, 4.4 KitKat, and 5.0-5.1 Lollipop.

MORE: 15 Cheap Tech Products That Make Life Easier

Phones and tablets running newer versions of Android, such as 6.0 Marshmallow or 7.0-7.1 Nougat, should be safe. Users can also protect themselves by installing all available security patches and version updates, running robust Android antivirus software and, most importantly, making sure that installing apps from "Unknown sources" is not enabled in their devices' security settings.

Gooligan is the latest variant on a strain of Android malware called Ghost Push that has been infecting Android users since 2014. Once it finds its way into handsets via malicious mobile apps, Ghost Push/Gooligan performs all kinds of annoying tasks, including sending users pop-ups ads and trying to install yet more apps, including some from the Google Play app store, on their handsets.

Gooligan threatens users' Google accounts, as it captures and reuses the authorization tokens that let Android devices permanently log into Google accounts. (Each token may take months to expire.) This lets Gooligan pose as a device user and submit phony five-star app reviews in the Google Play store. Check Point has posted a "Gooligan Checker" web page that lets users see whether their Google accounts may have been compromised.

Gooligan appears to be in the same vein as other Ghost Push malware. It lives inside compromised apps that are downloaded from third-party app stores. It's not believed to steal user data, but is part of what's essentially a sophisticated click-fraud scheme that collects cash from dodgy app developers every time Gooligan installs a new app or shows another ad on a victim's phone.

For its part, Google has been working hard to disrupt Ghost Push and its variants, according to a blog post yesterday (Nov. 29) by Android security chief Adrian Ludwig, who added that Google has tracked more than 40,000 Ghost Push apps. Ludwig said the company has taken action against the malware, including attempts at disrupting the command-and-control servers that try to peddle the malicious software.

Don Reisinger is CEO and founder of D2 Tech Agency. A communications strategist, consultant, and copywriter, Don has also written for many leading technology and business publications including CNET, Fortune Magazine, The New York Times, Forbes, Computerworld, Digital Trends, TechCrunch and Slashgear. He has also written for Tom's Guide for many years, contributing hundreds of articles on everything from phones to games to streaming and smart home.

Latest in Android Phones
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Samsung Galaxy S25 Ultra vs S25 Plus vs S25
Satellite messaging on Google Pixel 9 and Samsung Galaxy S25 just landed on 3 more carriers
back of Iris Pixel 9a
The Google Pixel 9a is lacking one of the Pixel 9’s best safety features — here’s what we know
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now