Google Play Removes 25 Apps Caught Stealing Facebook Credentials From Users: Evina

Cyber-security firm, Evina notes that these 25 apps collectively had over 25 lakh downloads.

Advertisement
By Abhik Sengupta | Updated: 1 July 2020 13:37 IST
Highlights
  • Most of the malicious apps offered wallpapers, video editing tools
  • Google removed these apps earlier in June
  • It is unclear how the apps avoided Google Play Protect detection

Users' Facebook credentials were sent to a remote server

Photo Credit: Evina

Google is said to have removed 25 apps from its Google Play store that were caught stealing Facebook credentials. According to the French cyber-security firm, Evina, these malicious apps collectively had over 25 lakh downloads. The apps reportedly offered different functionalities, though they used the same method for extracting users' credentials. Some of the apps had been available on the Google Play store for over two years before they were finally removed, the cyber-security firm highlighted.

The findings were published in a blog post by Evina and were first reported by ZDNet. Google removed the apps earlier in June after the cyber-security firm reported its potential threat in May this year. Most of these malicious apps offered new wallpapers, while others provided video editing tools and flashlight tools. Apps such as Super Wallpapers Flashlight and Padenatef had over 5 lakh downloads each on Google Play.

How did the apps steal Facebook credentials?

According to Evina, once the user launched the contentious app on their smartphone, the malicious app detected what app a user recently opened and had in the phone's foreground. "If it is a Facebook application, the malware will launch a browser that loads Facebook at the same time. The browser is displayed in the foreground which makes you think that the application launched it," the cyber-security firm explains.

Advertisement

Once the user put their Facebook login details on the phishing page (which features a black bar instead of a blue bar of the original Facebook app), the malicious then sent the credentials to a remote server. This could potentially allow attackers to access all data stored on the Facebook account or even allow them to access other websites where users' have logged in via their Facebook account.

Advertisement

Evina, however, has not clarified how these malicious apps avoided detection by Google's Play Protection service. The full list of these malicious Android apps is listed on Evina's website.

ZDNet citing the cyber-security firm notes that all of the 25 malicious apps were developed by a single threat group.


In 2020, will WhatsApp get the killer feature that every Indian is waiting for? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy Tab A11, Tab A11+ Design, Features Leaked Ahead of Launch
  2. iPhone 17 Pro Max Cosmic Orange Variant Out of Stock in the US, India: Report
  3. These New AI Features Are Coming to Your Updated iPhone, iPad and Mac
  4. iPhone 16 Pro, iPhone 16 Pro Max Offers Listed Ahead of Flipkart Sale
  5. Oppo Find X9 Pro Chipset, AnTuTu and Geekbench Scores Revealed
  6. iPhone 17 Series, iPhone Air Pre-Order Discounts Announced by Retailers in India
  7. Early Deals on PlayStation 5 and Accessories Revealed Ahead of Amazon Sale
  8. Xiaomi 17 Pro Render Gives Us a Good Look at Its Rear Display, Cameras
  9. Google Pixel 10 Review: A Brilliant Phone We Wanted to Love
  10. Vivo V60e Price in India, Specifications Surface Ahead of Launch
  1. Google Search App for Windows Launched With Spotlight-Like Features
  2. Flipkart Big Billion Days Sale 2025: Discounts on iPhone 16 Pro, iPhone 16 Pro Max Listed Ahead of Sale
  3. YouTube Announces New AI-Powered Tools for Shorts Creators, Podcasters at Made on YouTube Event
  4. Xiaomi 17 Pro Design Teased Again as Smartphone Appears on Geekbench With Snapdragon 8 Elite Gen 5 SoC
  5. Moto G36 Design and Features Revealed by TENAA Listing; Likely to Feature 6,790mAh Battery, 6.72-Inch Display
  6. iPhone 17 Series, iPhone Air Pre-Order Discounts Announced by Croma, Ingram Micro India, and Vijay Sales
  7. Vivo V60e Price and Specifications Reportedly Surface Ahead of India Launch
  8. OpenAI Plans Stricter Protections for Teens, Expands Privacy for Adult Users
  9. Sony Said to Be Planning State of Play Broadcast for Next Week
  10. France Could Block Crypto Firms With MiCA Licenses Due to Enforcement Gap Concerns
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.