Google Play Store Removes Nine Malicious Apps That Reportedly Stole Users Facebook Login Credentials

These nine malicious apps on the Google Play store said to have had five different variants of malware.

Advertisement
By Satvik Khare | Updated: 5 July 2021 17:13 IST
Highlights
  • Google has also banned the developers of these apps from the store
  • Users with these apps should scan their devices, Facebook accounts
  • The apps had approximately 5.9 million combined downloads

Google Play Store has now removed these nine apps

Photo Credit: Dr. Web

Google has removed nine apps from its Play store after researchers showed that they sneakily stole users' Facebook login credentials. The apps were hidden under names that sounded like everyday utility tools and apps. These include Rubbish Cleaner and Horoscope Daily. According to a report, the malicious apps had approximately 5.9 million combined downloads on the Google Play store — with PIP Photo alone having 5.8 million downloads — and had five different variants of malware. Google had earlier removed three apps meant for children over privacy violations.

Dr. Web, an antivirus service, reports that their malware analysts discovered nine malicious apps - Processing Photo, App Lock Keep, Rubbish Cleaner, Horoscope Daily, Horoscope Pi, App Lock Manager, Lockit Master, Inwell Fitness, and PIP Photo. These apps reportedly acted as trojan malware and stole users' Facebook login credentials after providing users the options to disable ads by logging in via their social media accounts. Dr. Web's report was spotted by Ars Technica.

These apps tricked users by showing an exact replica of Facebook's login page. The apps instead loaded a JavaScript command that stole their login credentials. The apps also apparently stole browser cookies from the authorisation session. There were a total of malware variants and all of them reportedly used an identical JavaScript code to steal user data. The report also noted that out of the malware variants, three were native Android apps, and two were created using Google's Flutter SDK.

Advertisement

The malware variants identified by Dr. Web are Android.PWS.Facebook.13Android.PWS.Facebook.14, Android.PWS.Facebook.15, Android.PWS.Facebook.17, and Android.PWS.Facebook.18.

A Google spokesperson told Ars Technica that they had also banned the app developers of all of the nine apps from Google Play store, which would stop these developer accounts from publishing any new apps on the marketplace. This is a positive step by Google, but a new developer account, under a different name, can be created with a nominal fee of $25 (roughly Rs. 1,900).

Users are advised not to download any app from an unknown developer, regardless of how many downloads the app might have. In this case, PIP Photo had the maximum downloads at 5.8 million, followed by Processing Photo at 500,000 downloads. Anyone who has downloaded these apps should thoroughly examine their device and Facebook account for suspicious activities.


Windows 11 has been unveiled, but do you need it? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Sale 2025: These Are the Best Deals on Budget Projectors
  2. Xiaomi Pad Mini With Dimensity 9400+ SoC Launched: Check Price
  3. Xiaomi 15T Pro With Dimensity 9400+ Launched Alongside Xiaomi 15T
  4. Oppo Reno 14 5G Diwali Edition Launched in India: See Price, Features
  5. Redmi Pad 2 Pro With Snapdragon 7s Gen 4 SoC Launched: See Price, Features
  6. Xiaomi TV S Pro Mini LED 2026 Series With 4K Displays Debuts in Three Sizes
  7. YouTube's AI Age Estimation Tool Is Now Restricting User Accounts
  8. OnePlus May Launch the First Global Snapdragon 8 Gen 5 Smartphone
  1. Bitcoin Price Drops Below $112,000 Ahead of $22.6 Billion Futures Expiry
  2. Oppo Reno 14 5G Diwali Edition Launched in India With Temperature-Sensitive Colour Changing Rear Panel
  3. OnePlus Tipped to Launch First Snapdragon 8 Gen 5 Phone; Snapdragon 8 Elite Gen 5-Powered Handsets to Launch in October
  4. YouTube Expands AI-Powered Age Estimation Tool, Tightens Restrictions on Several Accounts
  5. Google Launches Search Live in AI Mode With Video, Voice Search Support: How to Use the New Feature
  6. iOS 26.1 Beta Hints at Better Support for Other Smartwatches; Testers Get Access to New Apple Music Gestures
  7. Microsoft Adds OpenAI-Rival Anthropic’s Claude AI Models to Copilot
  8. Apple Explains Reason Behind 'Scratchgate' Issue on iPhone 17 Pro Demo Units
  9. CMF by Nothing to Operate as Independent Subsidiary With Manufacturing, Operations Based in India
  10. Marvel's Wolverine Gets Visceral Gameplay Trailer at State of Play, Sets Fall 2026 Launch Window
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.