Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • The Hacker News
  • PlayPraetor Reloaded: CTM360 Uncovers a Play Masquerading Party
  • The Hacker News

PlayPraetor Reloaded: CTM360 Uncovers a Play Masquerading Party

[email protected] The Hacker News Published: April 10, 2025 | Updated: April 10, 2025 4 min read
1 views

Overview of the PlayPraetor Masquerading Party Variants

CTM360 has now identified a much larger extent of the ongoing Play Praetor campaign. What started with 6000+ URLs of a very specific banking attack has now grown to 16,000+ with multiple variants. This research is ongoing, and much more is expected to be discovered in the coming days.

As before, all the newly discovered play impersonations are mimicking legitimate app listings, deceiving users into installing malicious Android applications or exposing sensitive personal information. While these incidents initially appeared to be isolated, further investigation has revealed a globally coordinated campaign that poses a significant threat to the integrity of the Play Store ecosystem.

Evolution of the Threat

This report expands on the earlier research into PlayPraetor, highlighting the discovery of five newly identified variants. These variants reveal the campaign’s increasing sophistication in terms of attack techniques, distribution channels, and social engineering tactics. The continuous evolution of PlayPraetor demonstrates its adaptability and persistent targeting of the Android ecosystem.

Variant-Specific Targeting and Regional Focus

In addition to the original PlayPraetor Banking Trojan, five new variants—Phish, RAT, PWA, Phantom, and Veil—have been identified. These variants are distributed through fake websites that closely resemble the Google Play Store. Although they share common malicious behaviors, each variant exhibits unique characteristics tailored to specific regions and use cases. Targeted regions include the Philippines, India, South Africa, and various global markets.

These variants employ a mix of credential phishing, remote access capabilities, deceptive web app installations, abuse of Android accessibility services, and stealth techniques that hide malicious activity behind legitimate branding.

Attack Objectives and Industry Focus

While each variant has unique features and regional targeting, a common theme across all PlayPraetor samples is their focus on the financial sector. Threat actors behind these variants seek to steal banking credentials, credit/debit card details, digital wallet access, and, in some cases, execute fraudulent transactions by transferring funds to mule accounts. These monetization strategies indicate a well-organized operation focused on financial gain.

Variant Summary and Detection Insights

The five new variants—Phish, RAT, PWA, Phantom, and Veil—are currently under active investigation. Some variants have confirmed detection statistics, while others are still being analyzed. A comparative table summarizing these variants, their capabilities, and regional targets is included in the following section, along with detailed technical analysis.

Variant Name Functionality Description Target Industry Detected Cases (Approx.)
PlayPraetor PWA Deceptive Progressive Web App Installs a fake PWA that mimics legitimate apps, creates shortcuts on the home screen, and triggers persistent push notifications to lure interaction. Technology Industry, Financial Industry, Gaming Industry, Gambling Industry, e-commerce Industry 5400+
PlayPraetor Phish WebView phishing A WebView-based app that launches a phishing webpage to steal user credentials. Financial, Telecommunication, Fast Food Industry 1400+
PlayPraetor Phantom Stealthy Persistence & Command Execution Exploits Android accessibility services for persistent control. Runs silently, exfiltrates data, hides its icon, blocks uninstallation, and poses as a system update. Financial Industry, Gambling Industry, Technology Industry These variants are currently under investigation to determine their exact identities.
PlayPraetor RAT Remote Access Trojan Grants attackers full remote control of the infected device, enabling surveillance, data theft, and manipulation. Financial Industry
PlayPraetor Veil Regional & Invitation-based Phishing Disguises itself using legitimate branding, restricts access via invite codes, and imposes regional limitations to avoid detection and increase trust among local users. Financial Industry, Energy Industry

Geographic Distribution and Targeting Patterns

CTM360’s analysis indicates that while PlayPraetor variants are being distributed globally, certain strains exhibit broader outreach strategies than others. Notably, the Phantom-WW variant stands out for its global targeting approach. In this case, threat actors impersonate a widely recognized application with global appeal, allowing them to cast a wider net and increase the likelihood of victim engagement across multiple regions.

Among the identified variants, the PWA variant emerged as the most prevalent, with detection across a wide array of geographic regions. Its reach spans South America, Europe, Oceania, Central Asia, South Asia, and parts of the African continent, underscoring its role as the most widespread variant within the PlayPraetor campaign.

Other variants showed more specific regional targeting. The Phish variant was also distributed across multiple regions, though with slightly less saturation than PWA. In contrast, the RAT variant exhibited a notable concentration of activity in South Africa, suggesting a region-specific focus. Similarly, the Veil variant was observed primarily in the United States and select African nations, reflecting a more targeted deployment strategy.

How to Stay Safe

To mitigate the risk of falling victim to PlayPraetor and similar scams:

✅ Only download apps from the official Google Play Store or Apple App Store

✅ Verify app developers and read reviews before installing any application

✅ Avoid granting unnecessary permissions, especially Accessibility Services

✅ Use mobile security solutions to detect and block malware-infected APKs

✅ Stay updated on emerging threats by following cybersecurity reports

Read the full report to explore variant behaviors, detection insights, and actionable recommendations.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Twitter ï‚™ and LinkedIn to read more exclusive content we post.

About The Author

[email protected] The Hacker News

See author's posts

Original post here

What do you feel about this?

  • The Hacker News

Post navigation

Previous: GitHub Announces General Availability of Security Campaigns
Next: Study Identifies 20 Most Vulnerable Connected Devices of 2025

Author's Other Posts

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims grinex.jpg

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

April 19, 2026 0 0
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet botnet-ddos.jpg

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

April 19, 2026 0 0
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched defender.jpg

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

April 19, 2026 0 0
Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul google-ads-android.jpg

Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul

April 19, 2026 0 0

Related Stories

grinex.jpg
  • The Hacker News

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

[email protected] The Hacker News April 19, 2026 0 0
botnet-ddos.jpg
  • The Hacker News

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

[email protected] The Hacker News April 19, 2026 0 0
defender.jpg
  • The Hacker News

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

[email protected] The Hacker News April 19, 2026 0 0
google-ads-android.jpg
  • The Hacker News

Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul

[email protected] The Hacker News April 19, 2026 0 0
nist-cve.jpg
  • The Hacker News

NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions

[email protected] The Hacker News April 17, 2026 0 1
europol.jpg
  • The Hacker News

Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts

[email protected] The Hacker News April 17, 2026 0 0

Trending Now

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims grinex.jpg 1

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

April 19, 2026 0 0
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet botnet-ddos.jpg 2

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

April 19, 2026 0 0
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched defender.jpg 3

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

April 19, 2026 0 0
Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul google-ads-android.jpg 4

Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul

April 19, 2026 0 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims grinex.jpg 1
  • The Hacker News

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

April 19, 2026 0 0
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet botnet-ddos.jpg 2
  • The Hacker News

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

April 19, 2026 0 0
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched defender.jpg 3
  • The Hacker News

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

April 19, 2026 0 0
Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul google-ads-android.jpg 4
  • The Hacker News

Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul

April 19, 2026 0 0
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions nist-cve.jpg 5
  • The Hacker News

NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions

April 17, 2026 0 1
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts europol.jpg 6
  • The Hacker News

Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts

April 17, 2026 0 0
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation apachemq.jpg 7
  • The Hacker News

Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation

April 17, 2026 0 0

You may have missed

grinex.jpg
  • The Hacker News

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

[email protected] The Hacker News April 19, 2026 0 0
botnet-ddos.jpg
  • The Hacker News

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

[email protected] The Hacker News April 19, 2026 0 0
defender.jpg
  • The Hacker News

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

[email protected] The Hacker News April 19, 2026 0 0
google-ads-android.jpg
  • The Hacker News

Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul

[email protected] The Hacker News April 19, 2026 0 0
Copyright © 2026 All rights reserved. | MoreNews by AF themes.