Google this month removed 25 Android apps from Play Store after they were found to be stealing Facebook credentials. These Android apps had been downloaded more than 2.34 million times by the time they were removed. The malicious apps were developed by the same threat actor, and while they offered users different features, they all worked “under the hood” in exactly the same way.
According to a report by French cybersecurity firm Evina, Android apps are posing as mobile, pedometers, file managers, editors , wallpaper apps, and lens apps. Despite offering legitimate functionality, these apps also contain malicious code. Evina researchers noted that the apps contained code that could detect which app a user had recently opened and which one was on their phone’s home screen.

The malicious Facebook app displayed a browser on top of the official Facebook app and loaded a fake Facebook login page. In the image below, the blue line depicts the real Facebook app and the black line the phishing page.

Every time users entered credentials on this phishing page, the malicious application recorded the data and sent it to a remote server located on the airshop.pw domain.
Evina found malicious code that stole Facebook credentials in 25 Android apps that were reported to Google about a month ago. Google removed the apps this month after the French security firm’s findings were verified. Some of the apps had been available on the Play Store for more than a year before they were removed. The full list of the 25 apps, along with their names and package IDs, is shown below. When Google removes malicious apps from the Play Store, it also disables the apps on a user’s device and notifies them through the service included in the official Play Store app.

