Google has removed nine popular Android apps from Google Play Store. It was found these apps stole user's Facebook login credentials. The apps were stealing user's data using identical Java script code.
In order to access all functions of the apps users were asked to log into their Facebook account . The Facebook page loaded into Android web view. The researchers discovered that hijackers also loaded malicious Java script into the same web view to steal user data.
These are the Nine Aps for Stealing Facebook Passwords
1. PIP Photo( 5,000,000 + Downloads)
2. Processing Photo ( 500,000+ Downloads)
3. Rubbish Cleaner (100,000+ Downloads)
4. Inwell Fitness (100,000+ Downloads)
5. Horoscope Daily ( 100,000 + Downloads)
6. App Lock Keep ( 50,000+ Downloads)
7. Horoscope Pi ( 1,000 downloads)
8. App Lock Manager (10 Downloads)
9.Lockit Master ( 5,000+ Downloads)
These are the Five Malware Variants identified inside the app
- Android P.W.S Facebook 13
- Android P.W.S Facebook 14
- Android P.W.S Facebook 15
- Android P.W.S Facebook 17
- Android P.W.S Facebook 18

No comments:
Post a Comment