Skip to content

Google kicks app with 5.8M downloads for stealing Facebook logins

Photo editors, horoscopes, and fitness apps amongst the genres found to be intercepting Facebook login data across nine apps.

Seamus Byrne
Seamus Byrne
1 min read
Google kicks app with 5.8M downloads for stealing Facebook logins

Researchers found a number of fully authorised apps in the Google Play Store were found to be stealing user credentials for Facebook in otherwise fully functional apps for tasks like photo editing, fitness, horoscopes and even the classic vector for dodgy things – pretending to help you clean up other dodgy things off your phone.

After researchers from security firm Dr. Web alerted Google to the problem apps, they were all removed. But they were vetted as clean apps by Google the first time around... so there's that...

The nine apps were:

  • Processing Photo
  • App Lock Keep
  • Rubbish Cleaner
  • Horoscope Daily
  • Horoscope Pi
  • App Lock Manager
  • Lockit Master
  • Inwell Fitness
  • PIP Photo

That last, PIP Photo, was the most downloaded with 5.8M, while the others ranged from 10 to 100,000 downloads.

The apps were largely appearing to be advertising supported, with an offer to remove the ads by asking you to login to Facebook. But the Facebook login was hijacking the user credentials during this authorisation process.

As ever, stay careful out there, and don't trust reviews or download numbers alone. These apps really worked and did what they said they did, so don't think you'll see flashing lights saying 'SCAM' to warn you something is up.

SecurityBusinessTechnologyAndroidGoogle

Seamus Byrne Twitter

Founder and Head of Content at Byteside.


Related Posts

The big 2024 iPad line up refresh is here

Apple drops the M4 processor into iPad Pro before anything else, plus an all-new Apple Pencil, new iPad Air, and a price drop on the base iPad. A big day for the tablet.

Promo image of the new iPad Pro on a white background

Google reveals the Pixel 8a

Following last year's Pixel 8 series, Google just announced the Pixel 8a with a big focus on AI-powered everything.

Paleblue lets you keep traditional batteries charged on the go

Just when you thought traditional batteries were dead, here comes Paleblue with a full range of classic cells that recharge over USB.

Four AA batteries being charged on USB via a laptop USB port.