Google removes popular Android apps that stole Facebook passwords

Google is still racing to pull Android apps that commit major privacy violations. Ars Technica notes that Google has removed nine apps from the Play Store after Dr. Web analysts discovered they were trojans stealing Facebook login details. These weren’t obscure titles — the malware had over 5.8 million combined downloads and posed as easy-to-find titles like “Horoscope Daily” and “Rubbish Cleaner.”

The apps tricked users by loading the real Facebook sign-in page, only to load JavaScript from a command and control server to “hijack” credentials and pass them along to the app (and thus the command server). They would also steal cookies from the authorization session. Facebook was the target in each case, but the creators could just have easily steered users toward other internet services.

There were five malware variants in the mix, but all of them used the same JavaScript code and configuration file formats to swipe information.

Google told Ars it banned all the app developers from the store, although that might not be much of a deterrent when the perpetrators can likely create new developer accounts. Google may need to screen for the malware itself to keep the attackers out.

The question, of course, is how the apps racked up as many downloads as they did before the takedown. Google’s largely automated screening keeps a lot of malware out of the Play Store, but the subtlety of the technique might have helped the rogue apps slip past these defenses and leave victims unaware that their Facebook data fell into the wrong hands. Whatever the cause, it’s safe to say that you should be cautious about downloading utilities from unknown developers no matter how popular they seem.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechNewsBoy.com is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.