Gooligan
MITRE ATT&CK: S0290 View on attack.mitre.org
Aliases: Ghost Push, Gooligan
- First seen
- 2016-11-29 00:00:00
- Malware type
- trojan, credential-stealer
- Family
- Malware family
- Operating systems
- android
- Profile updated
- 2026-07-07 15:29:13
Targeted industries: technology-and-telecommunications
Context
Gooligan is a malware family that runs privilege escalation exploits on Android devices and then uses its escalated privileges to steal authentication tokens that can be used to access data from many Google applications. Gooligan has been described as part of the Ghost Push Android malware family.
Malware & tools used
- Generate Traffic from Victim (attack-pattern)
- Data from Local System (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
Reports & references
- blog.checkpoint.com — 1 Million Google Accounts Breached Gooligan (report)
- MITRE ATT&CK — S0290 (report)
- blog.lookout.com — Ghost Push Gooligan (report)
- plus.google.com — Gxzj8Vaafsi (report)