Gooligan

MITRE ATT&CK: S0290 View on attack.mitre.org

Aliases: Ghost Push, Gooligan

First seen
2016-11-29 00:00:00
Malware type
trojan, credential-stealer
Family
Malware family
Operating systems
android
Profile updated
2026-07-07 15:29:13

Targeted industries: technology-and-telecommunications

Context

Gooligan is a malware family that runs privilege escalation exploits on Android devices and then uses its escalated privileges to steal authentication tokens that can be used to access data from many Google applications. Gooligan has been described as part of the Ghost Push Android malware family.

Malware & tools used

  • Generate Traffic from Victim (attack-pattern)
  • Data from Local System (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)

Reports & references

  • blog.checkpoint.com — 1 Million Google Accounts Breached Gooligan (report)
  • MITRE ATT&CK — S0290 (report)
  • blog.lookout.com — Ghost Push Gooligan (report)
  • plus.google.com — Gxzj8Vaafsi (report)

External references