Taking down Gooligan the infamous Android botnet – a retrospective analysis

Posted on Mar 20, 2018

Taking down Gooligan the infamous Android botnet – a retrospective analysis

This series of posts recounts how, in November 2016, we hunted for and took down Gooligan, the infamous Android OAuth stealing botnet. What makes Gooligan special is its weaponization of OAuth tokens, something that was never observed in mainstream crimeware before. At its peak, Gooligan had hijacked over 1M OAuth tokens in an attempt to perform fraudulent Play store installs and reviews.

Source: elie.net