Categories: Digital LifeTech

These Android apps might have stolen your Facebook password

Google has removed 9 apps due to them containing malicious code that steals users’ Facebook usernames and passwords. In total, the apps have clocked more than 5.8 million downloads.

Here’a a list of all the apps, with their respective download counts:

  • PIP Photo (5,000,000+ downloads)
  • Processing Photo (500,000+ downloads)
  • Rubbish Cleaner (100,000+ downloads)
  • Inwell Fitness (100,000+ downloads)
  • Horoscope Daily (100,000+ downloads)
  • App Lock Keep (50,000+ downloads)
  • Lockit Master (5,000+ downloads)
  • Horoscope Pi (1,000+ downloads)
  • App Lock Manager (10 downloads)

Google has since removed these apps from the Play Store and banned the developers from ever submitting another application (although the hackers can simply pay a small fee for another developer account and submit more malware).

Here’s how it worked: These apps look innocent on the surface. They function just like regular photo editing, horoscope, or device cleaning apps, but some functions are locked. To unlock all of the functions, the user must log into their Facebook account. The app then takes your username and password, and sends it to cybercriminals.

As explained by security firm Dr. Web, the scheme uses a special mechanism that uses a ‘command-and-control’ server. The credentials entered by the user get automatically sent to this C&C server, where they use JavaScript to get the data from the actual Facebook login page. They also collect cookies from the same session.

There have been 5 malware variants identified within the apps:

  • Android.PWS.Facebook.13
  • Android.PWS.Facebook.14
  • Android.PWS.Facebook.15
  • Android.PWS.Facebook.17
  • Android.PWS.Facebook.18

Dr. Web says that are all the same trojan.

If you think you have downloaded one of these apps, consider changing your Facebook password. If you tend to use the same password for multiple websites and services, I highly recommend getting a password manager and changing all your passwords to be distinct and randomly generated. This way, if a hacker gets to one of your accounts, they won’t be able to use that information for anything else. Lastly, enabling two-factor authorization whenever possible can greatly boost the security of your online accounts.

[ SOURCE ]

Recent Posts

RedMagic Astra 2 Malaysia: Snapdragon 8 Elite Gen 5 tablet with 185Hz OLED display, promo priced from RM3,599

RedMagic has officially launched its 2026 flagship gaming tablet in Malaysia, the RedMagic Astra 2.…

8 hours ago

TNG eWallet records over RM1 billion inbound tourist spend during Visit Malaysia 2026

TNG Digital announced that international tourists spent over RM1 billion using TNG eWallet during the…

9 hours ago

KTMB EMUPlus adds Bandar Tasik Selatan stop from 4 to 6 September: Here’s what you need to know

Keretapi Tanah Melayu Berhad (KTMB) is adding Bandar Tasik Selatan as a temporary stop for…

9 hours ago

BYD Atto 3 Performance coming to Malaysia: 443hp AWD, 470km range, 220kW DC charging

Sime Motors will be expanding the 2026 BYD Atto 3 lineup with a new variant:…

10 hours ago

Xiaomi debuts Mijia Front Load Washer Dryer Pro in Malaysia for as low as RM2,399

In addition to the Redmi Note 17 Series, Xiaomi has also rolled out several new…

11 hours ago

Xiaomi Smart Band 11 Active, Redmi Watch 6 Series Malaysia: Promo price starts from RM119

The Redmi Note 17 Series might have been the star of Xiaomi’s big launch event…

12 hours ago

This website uses cookies.