Apps

These 9 Android Apps Were Stealing Facebook Passwords, Google Exposed Them

Google has identified and removed 9 Android apps, which together have been downloaded more than 5.8 million times, from the Play Store. During a security check, the apps were caught secretly stealing users’ Facebook credentials. This is reported by various online magazines including ArsTechnica. The fraudulent apps were discovered by a security team at Dr. Web antivirus.

“The applications were fully functional, which should weaken the vigilance of the potential victims. In order to access all functions of the apps and supposedly also to deactivate in-app advertising, users were asked to log into their Facebook account.” According to the security researchers at Dr. Web. “The advertising within some of the apps was actually there, and this maneuver was supposed to get Android device owners to take the requested actions.”

The apps masked their malicious intent by disguising themselves as photo editing, tweaking, fitness, and astrology programs, only to get victims to log into their Facebook accounts. Then the login details entered were hijacked using JavaScript code and sent to a server controlled by the fraudsters using a Trojan. It is not yet known whether other information was also stolen in the process. After Dr. Web removes the apps.

Android Apps List

  • PIP Photo (> 5,000,000 installations)
  • Processing Photo (> 500,000 installations)
  • Rubbish Cleaner (> 100,000 installations)
  • Daily horoscope (> 100,000 installations)
  • Inwell Fitness (> 100,000 installations)
  • App Lock Keep (50,000 installs)
  • Lockit Master (5,000 installations)
  • Horoscope Pi (> 1,000 installations)
  • App Lock Manager (10 installations)

Users have to delete the apps themselves

The apps went unnoticed in the Google PlayStore for months. In order to permanently remove the apps, users have to manually delete them themselves. While this particular campaign targeted Facebook accounts, the Dr. Web researchers said this attack could easily be extended to load the login page of any legitimate web platform with the aim of stealing logins and passwords from a variety of services.

Recent Posts

Microsoft finally wants to fix Xbox download problems

Fluctuating rates, overloaded servers and frozen updates often plague Xbox users. Microsoft is now intervening…

1 day ago

ClickFix attack discovered: Hackers spread harmful help on Steam

An attack campaign is currently underway in the Steam discussion forums, in which criminals pose…

1 day ago

Samsung Galaxy: New cell phone batteries with a step backwards in terms of longevity

Samsung is equipping its new folding smartphones with modern silicon-carbon batteries. This brings more capacity…

1 day ago

Exchange Online: Stupid email glitch sends too much into quarantine

Many Exchange Online users are struggling with unexpected problems. A bug suddenly moves harmless emails…

1 day ago

Microsoft solves Azure problem: Updates and Store are running again

After a widespread failure of the Azure infrastructure, central Windows services are working again. Users…

1 day ago

Ryzen 7 9800HX3D: AMD is probably planning an affordable gaming laptop CPU

AMD is reportedly preparing a new X3D laptop processor for demanding gamers. The upcoming CPU…

1 day ago