Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Lovable just backed a company that’s looking to bring vibe coding to hardware

    May 14, 2026

    Clio’s $500M milestone arrives just as Anthropic ups the ante

    May 14, 2026

    Anduril raises $5B, doubles valuation to $61B

    May 13, 2026
    Facebook X (Twitter) Instagram
    Tech Pulse
    • Lovable just backed a company that’s looking to bring vibe coding to hardware
    • Clio’s $500M milestone arrives just as Anthropic ups the ante
    • Anduril raises $5B, doubles valuation to $61B
    • Kevin Hartz’s A* just closed its third fund with $450M
    • Riding an AI rally, Robinhood preps second retail venture IPO
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Techurz
    • Home
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    Techurz
    Home - Apps - Over 11,000 Android devices hit by fake login RAT hidden in Meta Ads and fake Google Play store
    Apps

    Over 11,000 Android devices hit by fake login RAT hidden in Meta Ads and fake Google Play store

    TechurzBy TechurzAugust 4, 2025Updated:May 11, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Mobile
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • Meta Ads and an SMS campaign is driving traffic to hundreds of fake Play Store pages
    • There, victims download fake apps that carry the PlayPraetor malware
    • The malware can log keystrokes, grab credentials, and monitor the clipboard

    More than 11,000 Android devices were recently infected by a new variant of the PlayPraetor remote access trojan (RAT).

    This is according to cybersecurity researchers Cleafy, who said that there is an ongoing, aggressive campaign to distribute the malware to as many devices as possible. So far, the RAT creates more than 2,000 new infections every week, targeting mostly devices in Portugal, Spain, France, Morocco, Peru, and Hong Kong.

    PlayPraetor is apparently a Chinese piece of malware, The Hacker News reports. Citing previous research, the publication claims there are “thousands” of fake Google Play Store download pages, advertised through Meta Ads and SMS messages, in an attempt to reach as big of an audience as it can. So far, the researchers spotted five distinct variants of PlayPraetor, among which is one called Phantom, and a variant called Phish.


    You may like

    Hundreds of spoofed apps

    Those that end up installing the malware can expect to lose their banking credentials, have their clipboard tracked, and their keystrokes/taps logged. At the moment, PlayPreator can impersonate more than 200 banking apps and cryptocurrency wallets, as it delivers an overlay that steals the login credentials.

    Besides pretending to be actual apps, the malware is also distributed through fake Progressive Web Apps (PWA), as well as WebView-based apps. The latter was observed in the Phish variant while Phantom, for example, exploits accessibility services to obtain persistent access.

    This variant also grants the attackers the ability to conduct on-device fraud and is apparently operated by two affiliates who control almost two-thirds of the botnet (around 4,500 endpoints).

    To defend against such attacks, the best course of action is to be careful when downloading apps, and only go for those listed on official repositories such as the Play Store. Even there, users should only go for apps developed by well-established brands, which have thousands of downloads and positive reviews.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Via The Hacker News

    You might also like

    ads Android Devices Fake Google hidden Hit login Meta play RAT Store
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHere’s How Small Businesses Can Survive
    Next Article I switched to this paper-like TCL phone for a week, and my tired eyes finally got a break
    Techurz
    • Website

    Related Posts

    Opinion

    Ramp in talks to hit $40B+ valuation, 6 months after reaching $32B

    May 7, 2026
    Opinion

    DeepSeek could hit $45B valuation from its first investment round

    May 6, 2026
    Opinion

    Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project

    April 1, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Lovable just backed a company that’s looking to bring vibe coding to hardware

    May 14, 2026

    Clio’s $500M milestone arrives just as Anthropic ups the ante

    May 14, 2026

    Anduril raises $5B, doubles valuation to $61B

    May 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.