Gooligan

Gooligan is a malware family that runs privilege escalation exploits on Android devices and then uses its escalated privileges to steal authentication tokens that can be used to access data from many Google applications. Gooligan has been described as part of the Ghost Push Android malware family. [1] [2] [3]

ID: S0290
Associated Software: Ghost Push
Type: MALWARE
Platforms: Android
Version: 1.2
Created: 25 October 2017
Last Modified: 24 October 2022

Associated Software Descriptions

Name Description
Ghost Push

Gooligan has been described as being part of the Ghost Push Android malware family. [2] [3]

Techniques Used

Domain ID Name Use
Mobile T1533 Data from Local System

Gooligan steals authentication tokens that can be used to access data from multiple Google applications.[1]

Mobile T1404 Exploitation for Privilege Escalation

Gooligan executes Android root exploits.[1]

Mobile T1643 Generate Traffic from Victim

Gooligan can install adware to generate revenue.[1]

References