/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Google removes nine Play Store apps, including PIP Photo with 5.8M+ downloads, after researchers found the apps were stealing users' Facebook login credentials

delete them now JC Torres / SlashGear : Popular Google Play Store apps removed for stealing Facebook passwords Rob Thubron / TechSpot : Nine apps with 5.8 million downloads kicked from Google Play store for stealing Facebook passwords Duncan Riley / SiliconANGLE : Nine apps stealing Facebook login credentials pulled from Google Play Nehal Malik / iPhone in Canada Blog : Android Apps with 6.5 Million Downloads Stole Facebook Passwords: Study Nathaniel Mott / PCMag : Google Kicks Credential-Stealing Android Apps from the Play Store Paul Lilly / HotHardware.com News : These Malware-Laced Android Apps Are Probably Stealing Your Facebook Password Argam Artashyan / Gizchina : 9 Android Apps Stole Facebook Passwords To Access Other User Data And Accounts Habiba Rashid / HackRead : 9 apps with 6M installs stole Facebook logins of Android users Alyse Stanley / Gizmodo : These Nine Android Apps May Have Stolen Your Facebook Login Information Alan Friedman / PhoneArena : These Android apps appear normal but steal your Facebook password; uninstall them immediately Chris Smith / BGR : These 9 Android apps might have stolen your Facebook password Tweets: Alex Russell / @slightlylate : At the bottom of this security issue is an OS choice to allow native apps to disrespect user choice of browser, and suborning developer intent on pages that would otherwise opt out of “in app browsers”. This one is on Android. Tuna Toksoz / @tehlike : @alexbilz @GeorgeBevis @rabois https://arstechnica.com/... Another one. All you need is to show a page inside an app and ask their password for some confidential stuff. People just give it. This is also why 2fa is important. Michael Love / @elkmovie : Apps which were in their store + had passed human (not ‘largely automated’ - it takes longer than Apple!) app review. Yet somehow sideloading is the reason Android has so much malware. https://twitter.com/... I.Zhilyakov / @m0br3v : Android Trojans that steal Facebook users' usernames, passwords and cookies were found on Google Play. They load the legitimate Facebook webpage into WebView. Then they load JS received from the C&C into the same WebView. https://news.drweb.com/... IoCs: https://github.com/... https://twitter.com/... Paolo Campisi / @pcampisi14 : I stopped coding and writing scripts in 2013, at that time the Facebook Access Token was the holy grail of shit you didn't want to expose, once someone had it you were fucked. I wonder if it's still the case. https://twitter.com/... @howtomen : If you downloaded any of these Android apps, CHANGE YOUR FACEBOOK PASSWORD NOW! These sneaky devs used a script from JavaScript to hijack the entered login credentials when they loaded up Facebook's login page on WebView. Apps are no long on the play store thankfully. SCARY!! https://twitter.com/... https://twitter.com/...

Ars Technica Dan Goodin

Context & Ripple Effects

Google’s removal follows a recurring Play Store enforcement pattern: researchers had already identified 25 Android apps using Facebook credential phishing overlays, and Google had also removed apps tied to scam ads. The new case shows that large download counts have not prevented credential-theft apps from reaching users through the store.

The immediate issue is not merely malicious functionality but distribution: apps presenting ordinary utility features can use Play Store reach to solicit Facebook credentials before researchers trigger a takedown.

First-order effects

  • Google removes the nine identified apps from Play Store distribution, while users who entered Facebook credentials into them face an account-security problem.
  • Facebook is the credential target in the reported campaign, making affected users’ Facebook logins the immediate asset exposed by the apps.

Second-order effects

  • Google’s app-review and post-publication enforcement process faces added pressure because the earlier Facebook-phishing app removals did not stop a subsequent, higher-download campaign.
  • Android utility-app publishers face more scrutiny around embedded login flows and WebView behavior, since seemingly routine app categories have been used to collect credentials.

Third-order effects

  • Repeated researcher-led removals point to Play Store governance becoming a continuing detection-and-takedown cycle rather than a one-time screening decision.
  • If credential theft keeps appearing in broadly distributed apps, trust in platform-controlled software delivery will depend increasingly on faster monitoring of apps after installation, not only admission checks.

The trend: Mobile app stores are becoming a persistent security control point as credential-phishing campaigns repeatedly exploit the distribution reach of ordinary-looking Android apps.

Discussion

  • @slightlylate Alex Russell on x
    At the bottom of this security issue is an OS choice to allow native apps to disrespect user choice of browser, and suborning developer intent on pages that would otherwise opt out of “in app browsers”. This one is on Android.
  • @tehlike Tuna Toksoz on x
    @alexbilz @GeorgeBevis @rabois https://arstechnica.com/... Another one. All you need is to show a page inside an app and ask their password for some confidential stuff. People just give it. This is also why 2fa is important.
  • @elkmovie Michael Love on x
    Apps which were in their store + had passed human (not ‘largely automated’ - it takes longer than Apple!) app review. Yet somehow sideloading is the reason Android has so much malware. https://twitter.com/...
  • @m0br3v I.Zhilyakov on x
    Android Trojans that steal Facebook users' usernames, passwords and cookies were found on Google Play. They load the legitimate Facebook webpage into WebView. Then they load JS received from the C&C into the same WebView. https://news.drweb.com/... IoCs: https://github.com/... ht…
  • @pcampisi14 Paolo Campisi on x
    I stopped coding and writing scripts in 2013, at that time the Facebook Access Token was the holy grail of shit you didn't want to expose, once someone had it you were fucked. I wonder if it's still the case. https://twitter.com/...
  • @howtomen @howtomen on x
    If you downloaded any of these Android apps, CHANGE YOUR FACEBOOK PASSWORD NOW! These sneaky devs used a script from JavaScript to hijack the entered login credentials when they loaded up Facebook's login page on WebView. Apps are no long on the play store thankfully. SCARY!! htt…