CTM360 has uncovered a significant expansion of the PlayPraetor malware campaign, which has grown from 6,000 to over 16,000 URLs. What initially appeared as isolated banking attacks has evolved into a sophisticated global operation targeting Android users through fake Google Play Store websites.
## Campaign Evolution and New Variants
Researchers have identified five distinct variants beyond the original banking trojan:
1. **PlayPraetor PWA** (5,400+ cases): Deploys deceptive Progressive Web Apps that mimic legitimate applications, creating persistent shortcuts and push notifications to lure users. Targets technology, financial, gaming, gambling, and e-commerce sectors.
2. **PlayPraetor Phish** (1,400+ cases): Uses WebView-based applications to launch phishing pages that steal credentials from financial, telecommunication, and fast food industry users.
3. **PlayPraetor Phantom**: Exploits Android accessibility services for persistent control, operating silently while exfiltrating data and blocking uninstallation attempts. Primarily targets financial, gambling, and technology sectors.
4. **PlayPraetor RAT**: Functions as a Remote Access Trojan, giving attackers complete control over infected devices for surveillance and data theft, focusing on financial institutions.
5. **PlayPraetor Veil**: Employs legitimate branding disguises with invitation codes and regional restrictions to avoid detection while targeting financial and energy sectors.
## Geographic Distribution
While the campaign has global reach, certain variants show specific targeting patterns:
– The **PWA variant** is most widespread, detected across South America, Europe, Oceania, Central Asia, South Asia, and parts of Africa.
– The **RAT variant** shows concentrated activity in South Africa.
– The **Veil variant** primarily targets the United States and select African nations.
– The **Phantom-WW variant** employs a global targeting approach by impersonating widely recognized applications.
## Protection Recommendations
To avoid PlayPraetor infections:
– Download apps exclusively from official app stores
– Verify developers and read reviews before installation
– Avoid granting unnecessary permissions, especially Accessibility Services
– Use mobile security solutions
– Stay informed about emerging threats
The campaign’s primary objective remains consistent across all variants: stealing financial credentials, payment card details, and digital wallet access to execute fraudulent transactions.
