This Android malware is hacking into your Google account to install apps

Devices running Android 4 and 5 have been affected.
 By 
Sasha Lekach
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Your Google accounts could have been compromised if you own a Android phone, thanks to a new malware variant known as "Gooligan."

The malware has infected more than 1 million accounts, according to research released Wednesday from cyber security company Check Point, and that figure is growing by a massive 13,000 devices per day.

In August, Gooligan emerged as a complex malware that infects devices after users download apps from third party stores. It was originally related to a malicious app from 2015 named SnapPea.


You May Also Like

The malware steals authentication tokens that can be used to access data from Google Play, Gmail, Google Docs, Google Drive and more. The malware installs certain apps on a user's phone and highly rates them. Its main mission is to install adware to generate revenue for those apps, reportedly raking in as much as $320,000 a month.

Check Point said that the hacked Google accounts are mostly in Asia, but 19 percent are in North and South America and 9 percent are in Europe. The malicious code appears to affect devices running Android 4 (in versions known as Jelly Bean and KitKat) and Android 5 (Lollipop).

To avoid infecting your device, you should only download apps from the official Google Play store. Check Point has built a site to check if your Google account was breached. If your phone is infected, things get a little more difficult. Check Point recommends installing a clean operating system on your phone. This is complicated, so it's best to turn off your device and get professional help. Once your phone has been fixed by a pro make sure you change all your Google passwords.

Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

When Mashable reached out to Google about the hack they referred us to a post published Tuesday by Adrian Ludwig, the company's director of Android security. It said that the security team had been working closing with Check Point for several weeks to "investigate and protect users."

Ludwig confirmed Gooligan uses Google credentials on older versions of Android to generate fraudulent app installs. "We’ve taken many actions to protect our users and improve the security of the Android ecosystem overall," he wrote. The company has found no evidence of the hackers accessing user data, he added.

Mashable Image
Sasha Lekach

Sasha is a news writer at Mashable's San Francisco office. She's an SF native who went to UC Davis and later received her master's from the UC Berkeley Graduate School of Journalism. She's been reporting out of her hometown over the years at Bay City News (news wire), SFGate (the San Francisco Chronicle website), and even made it out of California to write for the Chicago Tribune. She's been described as a bookworm and a gym rat.

Mashable Potato

Recommended For You
Popular Chrome extension disabled for containing malware
Google Chrome logo

Do you have one of these 17 browser extensions? They could be tracking your browsing history.
safari and chrome apps on phone

FBI investigates Steam games with hidden malware
Steam logo on laptop

Everything you need to know about the malware stealing data from Mac users
MacBook in the dark using Terminal

Newly discovered malware 'pranks' its victims – just in time for April Fools' Day
Hacker at laptop

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.


Google launches Gemma 4, a new open-source model: How to try it
Google Gemma
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!