Google Play Store Removes Nine Malicious Apps That Reportedly Stole Users Facebook Login Credentials

These nine malicious apps on the Google Play store said to have had five different variants of malware.

Advertisement
By Satvik Khare | Updated: 5 July 2021 17:13 IST
Highlights
  • Google has also banned the developers of these apps from the store
  • Users with these apps should scan their devices, Facebook accounts
  • The apps had approximately 5.9 million combined downloads

Google Play Store has now removed these nine apps

Photo Credit: Dr. Web

Google has removed nine apps from its Play store after researchers showed that they sneakily stole users' Facebook login credentials. The apps were hidden under names that sounded like everyday utility tools and apps. These include Rubbish Cleaner and Horoscope Daily. According to a report, the malicious apps had approximately 5.9 million combined downloads on the Google Play store — with PIP Photo alone having 5.8 million downloads — and had five different variants of malware. Google had earlier removed three apps meant for children over privacy violations.

Dr. Web, an antivirus service, reports that their malware analysts discovered nine malicious apps - Processing Photo, App Lock Keep, Rubbish Cleaner, Horoscope Daily, Horoscope Pi, App Lock Manager, Lockit Master, Inwell Fitness, and PIP Photo. These apps reportedly acted as trojan malware and stole users' Facebook login credentials after providing users the options to disable ads by logging in via their social media accounts. Dr. Web's report was spotted by Ars Technica.

Advertisement

These apps tricked users by showing an exact replica of Facebook's login page. The apps instead loaded a JavaScript command that stole their login credentials. The apps also apparently stole browser cookies from the authorisation session. There were a total of malware variants and all of them reportedly used an identical JavaScript code to steal user data. The report also noted that out of the malware variants, three were native Android apps, and two were created using Google's Flutter SDK.

The malware variants identified by Dr. Web are Android.PWS.Facebook.13Android.PWS.Facebook.14, Android.PWS.Facebook.15, Android.PWS.Facebook.17, and Android.PWS.Facebook.18.

A Google spokesperson told Ars Technica that they had also banned the app developers of all of the nine apps from Google Play store, which would stop these developer accounts from publishing any new apps on the marketplace. This is a positive step by Google, but a new developer account, under a different name, can be created with a nominal fee of $25 (roughly Rs. 1,900).

Advertisement

Users are advised not to download any app from an unknown developer, regardless of how many downloads the app might have. In this case, PIP Photo had the maximum downloads at 5.8 million, followed by Processing Photo at 500,000 downloads. Anyone who has downloaded these apps should thoroughly examine their device and Facebook account for suspicious activities.


Windows 11 has been unveiled, but do you need it? We discussed this on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy A57 5G: Smart Choice That Redefines Mid-Range Value
  2. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale
  3. These Four Motorola Phones Are Now Eligible to Get Android 17 Beta Updates
  4. Here's When the Oppo K15 Pro Series Could Be Launched in India
  5. Vivo T5 Pro 5G Confirmed to Launch in India Soon With These Features
  1. Microsoft Releases New AI Models That Can Generate Images, Audio and Transcribe Text
  2. Redmi K Pad 2, New Redmi Laptops Tipped to Launch Alongside Redmi K90 Ultra
  3. Google Pixel 10 Users Can Now Play Steam Games Offline via GameNative 0.9.0
  4. Circle Unveils cirBTC Token to Expand Bitcoin’s Role in DeFi Ecosystem
  5. Honor 600 Series Could Launch Soon as Company Starts Teasing Debut of a New Phone
  6. Microsoft AI Chief Wants to Deliver State-of-the-Art AI Models by 2027: Report
  7. Infinix GT 50 Pro Leak Shows Design, Cooling, Gaming Features Ahead of Anticipated Launch
  8. Samsung Galaxy Z Fold 8, Galaxy Z Flip 8 to Stick With Older M13 OLED Panels: Report
  9. Crypto Hack Losses Drop to $168.6 Million in Q1 2026 Despite Ongoing Risks
  10. Google Vids Will Now Let All Users Generate Veo 3.1 AI Videos for Free, New Features Added
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.