Mobile security firm Zimperium is warning of an Android trojan that may have stolen Facebook credentials from a large number of users.
The malware, named Schoolyard Bully Trojan by Zimperium, appears to mainly target Vietnam, but the security company is aware of more than 300,000 victims located across 71 countries.
“The actual number of countries could be more than what was accounted for because the applications are still being found in third-party app stores,” the security firm said.
Active since 2018, Schoolyard Bully has been delivered through innocent-looking Android applications hosted on Google Play and various third-party app stores. Google has removed the malware from its official app store, but the malicious applications are still available on other websites, Zimperium said.
The malware is often hidden inside what appear to be educational applications. Schoolyard Bully relies on JavaScript injections to display phishing pages designed to trick users into handing over their Facebook username and password.
The malware also helps the cybercriminals collect information such as Facebook profile name, Facebook ID, and device details.
Last year, Zimperium detailed a campaign called FlyTrap, which also involved an Android trojan designed to compromise Facebook accounts, and that operation was also linked to Vietnam. However, the company’s researchers believe, based on source code analysis, that FlyTrap and Schoolyard Bully are completely different campaigns.
Zimperium has made available technical information and indicators of compromise (IoCs) that can be used to detect Schoolyard Bully malware.
Related: ‘MaliBot’ Android Malware Steals Financial, Personal Information
Related: SharkBot Android Malware Continues Popping Up on Google Play

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- High-Severity Privilege Escalation Vulnerability Patched in VMware Workstation
- GoAnywhere MFT Users Warned of Zero-Day Exploit
- UK Car Retailer Arnold Clark Hit by Ransomware
- EV Charging Management System Vulnerabilities Allow Disruption, Energy Theft
- Unpatched Econolite Traffic Controller Vulnerabilities Allow Remote Hacking
- Google Fi Data Breach Reportedly Led to SIM Swapping
- Microsoft’s Verified Publisher Status Abused in Email Theft Campaign
- British Retailer JD Sports Discloses Data Breach Affecting 10 Million Customers
Latest News
- Fraudulent “CryptoRom” Apps Slip Through Apple and Google App Store Review Process
- US Downs Chinese Balloon Off Carolina Coast
- Microsoft: Iran Unit Behind Charlie Hebdo Hack-and-Leak Op
- Feds Say Cyberattack Caused Suicide Helpline’s Outage
- Big China Spy Balloon Moving East Over US, Pentagon Says
- Former Ubiquiti Employee Who Posed as Hacker Pleads Guilty
- Cyber Insights 2023: Venture Capital
- Atlassian Warns of Critical Jira Service Management Vulnerability
