Gooligan

Gooligan is a malware family that runs privilege escalation exploits on Android devices and then uses its escalated privileges to steal authentication tokens that can be used to access data from many Google applications. Gooligan has been described as part of the Ghost Push Android malware family. [1] [2] [3]

ID: S0290
Associated Software: Ghost Push
Type: MALWARE
Platforms: Android
Version: 1.1

Associated Software Descriptions

Name Description
Ghost Push Gooligan has been described as being part of the Ghost Push Android malware family. [2] [3]

Techniques Used

Domain ID Name Use
Mobile T1409 Access Sensitive Data or Credentials in Files Gooligan steals authentication tokens that can be used to access data from multiple Google applications.[1]
Mobile T1404 Exploit OS Vulnerability Gooligan executes Android root exploits.[1]
Mobile T1472 Generate Fraudulent Advertising Revenue Gooligan can install adware to generate revenue.[1]

References