HomeSecurityGoogle: Removes popular Android apps that stole Facebook credentials

Google: Removes popular Android apps that stole Facebook credentials

Google is working to remove Android apps that commit major privacy violations. As Ars Technica, the tech giant has removed nine apps from its after analysts at Dr. Web discovered that they contained trojans that stole Facebook user credentials. These malicious apps had over 5.8 million downloads and easy-to-find titles like “Horoscope Daily” and “Rubbish Cleaner.”

Read also: Google Android update: Storage of digital vaccination cards

The apps tricked users into loading the real Facebook login page, in order to load JavaScript from a C2 server, with the aim of stealing their credentials and passing them to the app (and therefore to the server). They also aimed to steal cookies from the authorization session. The target was Facebook. However, the creators could simply direct users to other online services.

Google Android apps - Facebook credentials
Google: Removes popular Android apps that stole Facebook credentials

There were five malware variants, but they all used the same JavaScript code and the same configuration file formats to steal information.

See also: Facebook to users: Are you worried that a friend is "becoming an extremist"?

Google said on Ars Technica that it banned all app developers from its store, although this will not prevent malicious actions, given that the actors» will likely create new developer accounts.

Google Android apps - Facebook credentials
Google: Removes popular Android apps that stole Facebook credentials

Recommendation: Joker Malware Strikes Again: Delete These 8 Android Apps Immediately

The question that arises in this case is: How did the apps have as many downloads as they did before the removal? Google's automated screening largely keeps a lot of malware out of its Play Store, but the subtlety of the technique could have helped malicious apps get past these defenses without Facebook users knowing that their data had fallen into the wrong hands. Therefore, users should be extra careful whenever downloading utilities from unknown developers, no matter how popular they may seem.

Information source: engadget.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS