Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Qodo raises $70M for code verification as AI coding scales

    March 30, 2026

    Elon Musk’s last co-founder reportedly leaves xAI

    March 28, 2026

    From Moon hotels to cattle herding: 8 startups investors chased at YC Demo Day

    March 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Qodo raises $70M for code verification as AI coding scales
    • Elon Musk’s last co-founder reportedly leaves xAI
    • From Moon hotels to cattle herding: 8 startups investors chased at YC Demo Day
    • Aetherflux reportedly raising Series B at $2 billion valuation
    • OpenAI shuts down Sora while Meta gets shut out in court
    • VCs are betting billions on AI’s next wave, so why is OpenAI killing Sora?
    • 16 of the most interesting startups from YC W’26 Demo Day
    • Defense startup Shield AI lands $12.7B valuation, up 140%, after US Air Force deal
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Apps»Over 11,000 Android devices hit by fake login RAT hidden in Meta Ads and fake Google Play store
    Apps

    Over 11,000 Android devices hit by fake login RAT hidden in Meta Ads and fake Google Play store

    TechurzBy TechurzAugust 4, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Mobile
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • Meta Ads and an SMS campaign is driving traffic to hundreds of fake Play Store pages
    • There, victims download fake apps that carry the PlayPraetor malware
    • The malware can log keystrokes, grab credentials, and monitor the clipboard

    More than 11,000 Android devices were recently infected by a new variant of the PlayPraetor remote access trojan (RAT).

    This is according to cybersecurity researchers Cleafy, who said that there is an ongoing, aggressive campaign to distribute the malware to as many devices as possible. So far, the RAT creates more than 2,000 new infections every week, targeting mostly devices in Portugal, Spain, France, Morocco, Peru, and Hong Kong.

    PlayPraetor is apparently a Chinese piece of malware, The Hacker News reports. Citing previous research, the publication claims there are “thousands” of fake Google Play Store download pages, advertised through Meta Ads and SMS messages, in an attempt to reach as big of an audience as it can. So far, the researchers spotted five distinct variants of PlayPraetor, among which is one called Phantom, and a variant called Phish.


    You may like

    Hundreds of spoofed apps

    Those that end up installing the malware can expect to lose their banking credentials, have their clipboard tracked, and their keystrokes/taps logged. At the moment, PlayPreator can impersonate more than 200 banking apps and cryptocurrency wallets, as it delivers an overlay that steals the login credentials.

    Besides pretending to be actual apps, the malware is also distributed through fake Progressive Web Apps (PWA), as well as WebView-based apps. The latter was observed in the Phish variant while Phantom, for example, exploits accessibility services to obtain persistent access.

    This variant also grants the attackers the ability to conduct on-device fraud and is apparently operated by two affiliates who control almost two-thirds of the botnet (around 4,500 endpoints).

    To defend against such attacks, the best course of action is to be careful when downloading apps, and only go for those listed on official repositories such as the Play Store. Even there, users should only go for apps developed by well-established brands, which have thousands of downloads and positive reviews.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Via The Hacker News

    You might also like

    ads Android Devices Fake Google hidden Hit login Meta play RAT Store
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHere’s How Small Businesses Can Survive
    Next Article I switched to this paper-like TCL phone for a week, and my tired eyes finally got a break
    Techurz
    • Website

    Related Posts

    Opinion

    OpenAI shuts down Sora while Meta gets shut out in court

    March 27, 2026
    Opinion

    Delve did the security compliance on LiteLLM, an AI project hit by malware

    March 26, 2026
    Opinion

    Insight Partners scrubs investment post about Delve amid ‘fake compliance’ allegations

    March 24, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Qodo raises $70M for code verification as AI coding scales

    March 30, 2026

    Elon Musk’s last co-founder reportedly leaves xAI

    March 28, 2026

    From Moon hotels to cattle herding: 8 startups investors chased at YC Demo Day

    March 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.