Google Play Store Removes Nine Malicious Apps That Reportedly Stole Users Facebook Login Credentials

These nine malicious apps on the Google Play store said to have had five different variants of malware.

Advertisement
By Satvik Khare | Updated: 5 July 2021 17:13 IST
Highlights
  • Google has also banned the developers of these apps from the store
  • Users with these apps should scan their devices, Facebook accounts
  • The apps had approximately 5.9 million combined downloads

Google Play Store has now removed these nine apps

Photo Credit: Dr. Web

Google has removed nine apps from its Play store after researchers showed that they sneakily stole users' Facebook login credentials. The apps were hidden under names that sounded like everyday utility tools and apps. These include Rubbish Cleaner and Horoscope Daily. According to a report, the malicious apps had approximately 5.9 million combined downloads on the Google Play store — with PIP Photo alone having 5.8 million downloads — and had five different variants of malware. Google had earlier removed three apps meant for children over privacy violations.

Dr. Web, an antivirus service, reports that their malware analysts discovered nine malicious apps - Processing Photo, App Lock Keep, Rubbish Cleaner, Horoscope Daily, Horoscope Pi, App Lock Manager, Lockit Master, Inwell Fitness, and PIP Photo. These apps reportedly acted as trojan malware and stole users' Facebook login credentials after providing users the options to disable ads by logging in via their social media accounts. Dr. Web's report was spotted by Ars Technica.

These apps tricked users by showing an exact replica of Facebook's login page. The apps instead loaded a JavaScript command that stole their login credentials. The apps also apparently stole browser cookies from the authorisation session. There were a total of malware variants and all of them reportedly used an identical JavaScript code to steal user data. The report also noted that out of the malware variants, three were native Android apps, and two were created using Google's Flutter SDK.

Advertisement

The malware variants identified by Dr. Web are Android.PWS.Facebook.13Android.PWS.Facebook.14, Android.PWS.Facebook.15, Android.PWS.Facebook.17, and Android.PWS.Facebook.18.

A Google spokesperson told Ars Technica that they had also banned the app developers of all of the nine apps from Google Play store, which would stop these developer accounts from publishing any new apps on the marketplace. This is a positive step by Google, but a new developer account, under a different name, can be created with a nominal fee of $25 (roughly Rs. 1,900).

Advertisement

Users are advised not to download any app from an unknown developer, regardless of how many downloads the app might have. In this case, PIP Photo had the maximum downloads at 5.8 million, followed by Processing Photo at 500,000 downloads. Anyone who has downloaded these apps should thoroughly examine their device and Facebook account for suspicious activities.


Windows 11 has been unveiled, but do you need it? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15R, OnePlus 15R Ace Edition Launch Today: All You Need to Know
  2. Xiaomi's HyperOS 3 Update Is Rolling Out to These Phones, Tablets
  3. Moto G Power (2026) Launched With MediaTek Dimensity 6300 SoC: Details
  4. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  5. Disney Is Keeping Its Options Open For Future AI Partnerships
  6. OpenAI Says ChatGPT Will Soon Become an Operating System
  7. Dhruv64: India's First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  8. Honor Power 2 Key Features Leaked; Could Launch With a 10,080mAh Battery
  9. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  1. Xiaomi 17 Ultra Reportedly Listed on US FCC and IMEI Databases, Hinting at Imminent Global Debut
  2. Moto G Power (2026) Launched With MediaTek Dimensity 6300 SoC, 5200mAh Battery: Price, Specifications
  3. OnePlus 15R, OnePlus 15R Ace Edition Launching Today: Know Price in India, Features, Specs and More
  4. Astronomers Witness Longest-Lasting Gamma-Ray Burst in History, 8 Billion Light-Years Away
  5. Sub-Millimeter Robots Can Sense, Think, and Act Autonomously, New Study Finds
  6. Earth’s Atmosphere Has Been Leaking Onto the Moon for Billions of Years, Study Finds
  7. New Orbital Clues Reveal How Hot Jupiters Moved Close to Their Stars
  8. Heartiley Battery Out on OTT: Know Where to Watch This Tamil Sci-Fi Series Online
  9. Raat Akeli Hai: The Bansal Murders OTT Release Date: When and Where to Watch it Online?
  10. Private Satellites Pinpoint Methane Emissions from Oil, Gas, and Coal Facilities Worldwide
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.