These Android apps only want to steal your Facebook login details

Phone malware
(Image credit: Shutterstock)

Google has removed 25 Android apps from the Google Play Store after it was discovered that they were stealing users' Facebook credentials.

The malicious apps, which were collectively downloaded more than 2.34m times, were all created by the same developer. While the apps appeared to be different from one another, they all shared the same code that enabled them to harvest the credentials of Facebook users.

The French cybersecurity firm Evina was the first to discover these apps and the company reported its findings to Google. The apps themselves posed as legitimate applications including step counters, image editors, video editors, wallpaper apps, flashlight apps, file managers and mobile games.

Stealing Facebook credentials

In a blog post, Evina provided more details on how these malicious apps stole users' Facebook credentials, saying:

“When an application is launched on your phone, the malware queries the application name. If it is a Facebook application, the malware will launch a browser that loads Facebook at the same time. The browser is displayed in the foreground which makes you think that the application launched it. When you enter your credentials into this browser, the malware executes java script to retrieve them. The malware then sends your account information to a server.”

Evina discovered these 25 malicious apps from the developer Rio Reader LLC and reported them to Google at the end of May. After verifying the firm's findings, Google removed the apps from the Play Store earlier this month.

However, some of the apps were available on the Play Store for more than a year before they were removed which means that the developers were able to steal the credentials of many Facebook users before their operation was shut down.

Via ZDNet

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost