• Hype
  • Murai
  • Lipstiq
  • Varnam
  • Hangat
  • Autofreaks
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Mobile Gaming
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
  • News
    • Lifestyle
    • Computing
    • Hardware
    • Internet
    • Rumours & Leaks
    • Software
  • Forums
    • Kopitiam
    • Tradezone
    • Property Talk
    • Finance & Business
    • Fast and Furious
  • Gaming
    • PC Gaming
    • Console
    • Mobile Gaming
    • Esports
  • Mobile
    • Apps
    • OS
    • Tablets
    • Phones
    • Telco
      • Celcom
      • DiGi
      • Maxis
      • Tune Talk
      • U Mobile
      • Buzzme
  • Pricelists
    • Compu-zoneUpdated
    • ViewnetUpdated
    • Sri ComputersUpdated
    • StartecUpdated
  • More
    • Automotive Tech
    • Drone
    • Enterprise
    • Entertainment
    • Fashion
    • E-Hailing
    • Wearables
No Result
View All Result
Lowyat.NET
No Result
View All Result
Home Mobile Apps

Google Removes Play Store Apps That Stole Users’ Facebook Passwords

Nine apps were removed for major privacy violations.

by Ikmal Rozlan
July 5, 2021
Share on WhatsappShare on TelegramThreads

Google is racing to identify apps that break Android’s user privacy policies. Ars Technica discovered that Google removed nine trojans posing as apps that stole Facebook login credentials from the Play Store. The malware had over 5.8 million combined downloads and used generic popular titles such as “Horoscope Daily” and “Rubbish Cleaner” on Google Play.

The apps tricked users by loading the Facebook sign-in page and redirecting it to a command and control server, which loaded JavaScript that then “hijacked” usernames and passwords and passed them to the app, thus the command server. To complete their goal, they would also swipe some cookies from the authorisation session.

While Facebook was the only target, in each case, the perpetrators could have easily redirected users toward alternative internet services. It was discovered that while there were five malware variants, they all used the same JavaScript code and configuration file formats to steal the information.

In response to an inquiry from Ars, Google stated that it had banned the offending developers from the store, though this may not pose much of a barrier for the perpetrators, as they can easily set up new developer accounts. To that end, it is possible that Google will have to screen for the malware itself in order to keep the scammers out.

Of course, the bigger question is how the apps ended up with so many downloads before they were removed. Thanks to the artificial intelligence and machine learning that Google has employed, the majority of malware online do not slip into the Play Store, but the finer points of the technique may have allowed certain rogue apps to bypass these parameters and allow their victims to remain unaware that their Facebook data had been compromised.

RELATED:  Here’s A Look At The Google Pixel Buds 2a In “Fog” And “Berry” Colours

Google Play Store

The damage this time isn’t so bad compared to when Google discovered that Camscanner, a popular app that had been downloaded over 100 million times, was riddled with malware. On another note, Google Play’s AI detected one million apps that violated the platform’s policies last year. Regardless of the underlying cause, it bears repeating that it’s important to be cautious about downloading apps from unknown developers, no matter how popular they appear to be.

(Sources: Engadget, Slash Gear // Image: portal gda / Flickr)

Filed Under GooglePlay Store
Updated 5:22 pm, Mon, 5 July 21
http://lowy.at/hzMie
SendShareShareShare1Tweet1

Follow us on Instagram, Facebook, Twitter or Telegram for more updates and breaking news. 

No Result
View All Result

TRENDING THIS WEEK

  1. 1
    News

    DBKL To Close Route Along Jalan Yew Bridge Starting 10 April 2026

  2. 2
    Mobile Phones

    HONOR 600 Series Design Revealed Ahead Of Local Launch

  3. 3
    Automotive

    Govt Studying MyKasih And MyKad Integration For Targeted Diesel Subsidies

  4. 4
    Audio

    Edifier M90 Speakers Now Available In Malaysia

  5. 5
    Gaming

    Second Capcom Pop-Up Event To Be Held In Johor Bahru From 14 To 19 April

NETWORK

  • Hype
  • Murai
  • Lipstiq
  • Varnam
  • Hangat
  • Autofreaks

ABOUT

  • Advertise
  • Careers
  • Privacy Statement
  • Editorial Policy
  • Terms of Use
  • Contact Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
  • Forums
  • Laptops
  • Telco
  • Mobile
  • Gaming
  • Fintech
  • Artificial Intelligence
  • Cryptocurrency
  • Cyber Security
  • Hybrid Vehicles
  • Advertise with Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.

No Result
View All Result
  • News
  • Forums
  • Laptops
  • Telco
  • Mobile
  • Gaming
  • Fintech
  • Artificial Intelligence
  • Cryptocurrency
  • Cyber Security
  • Hybrid Vehicles
  • Advertise with Us

©2026 VIJANDREN RAMADASS. ALL RIGHTS RESERVED.