Security Experts:

Connect with us

Hi, what are you looking for?


Malware & Threats

‘Schoolyard Bully’ Android Trojan Targeted Facebook Credentials of 300,000 Users

Mobile security firm Zimperium is warning of an Android trojan that may have stolen Facebook credentials from a large number of users.

Mobile security firm Zimperium is warning of an Android trojan that may have stolen Facebook credentials from a large number of users.

The malware, named Schoolyard Bully Trojan by Zimperium, appears to mainly target Vietnam, but the security company is aware of more than 300,000 victims located across 71 countries.

“The actual number of countries could be more than what was accounted for because the applications are still being found in third-party app stores,” the security firm said.

Active since 2018, Schoolyard Bully has been delivered through innocent-looking Android applications hosted on Google Play and various third-party app stores. Google has removed the malware from its official app store, but the malicious applications are still available on other websites, Zimperium said.

The malware is often hidden inside what appear to be educational applications. Schoolyard Bully relies on JavaScript injections to display phishing pages designed to trick users into handing over their Facebook username and password.

The malware also helps the cybercriminals collect information such as Facebook profile name, Facebook ID, and device details.

Last year, Zimperium detailed a campaign called FlyTrap, which also involved an Android trojan designed to compromise Facebook accounts, and that operation was also linked to Vietnam. However, the company’s researchers believe, based on source code analysis, that FlyTrap and Schoolyard Bully are completely different campaigns.

Zimperium has made available technical information and indicators of compromise (IoCs) that can be used to detect Schoolyard Bully malware.

Related: ‘MaliBot’ Android Malware Steals Financial, Personal Information

Related: SharkBot Android Malware Continues Popping Up on Google Play

Related: Fake Netflix App Luring Android Users to Malware

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Expert Insights

Related Content

Malware & Threats

Microsoft plans to improve the protection of Office users by blocking XLL add-ins from the internet.

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Technical details published for an Arm Mali GPU flaw leading to arbitrary kernel code execution and root on Pixel 6.

Mobile & Wireless

Apple’s iOS 12.5.7 update patches CVE-2022-42856, an actively exploited vulnerability, in old iPhones and iPads.


CISA, NSA, and MS-ISAC issued an alert on the malicious use of RMM software to steal money from bank accounts.


A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.


Chinese threat actor DragonSpark has been using the SparkRAT open source backdoor in attacks targeting East Asian organizations.