Gooligan

Gooligan is a malware family that runs privilege escalation exploits on Android devices and then uses its escalated privileges to steal authentication tokens that can be used to access data from many Google applications. Gooligan has been described as part of the Ghost Push Android malware family. [1] [2] [3]

ID: S0290
Associated Software: Ghost Push
Type: MALWARE
Platforms: Android
Version: 1.2
Created: 25 October 2017
Last Modified: 10 October 2019

Associated Software Descriptions

Name Description
Ghost Push

Gooligan has been described as being part of the Ghost Push Android malware family. [2] [3]

Techniques Used

Domain ID Name Use
Mobile T1533 Data from Local System

Gooligan steals authentication tokens that can be used to access data from multiple Google applications.[1]

Mobile T1404 Exploit OS Vulnerability

Gooligan executes Android root exploits.[1]

Mobile T1472 Generate Fraudulent Advertising Revenue

Gooligan can install adware to generate revenue.[1]

References