• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
TechEngage

TechEngage®

Hands-on reviews, research-backed buying guides and technology news.

  • News
    • Internet & Social
    • Gadgets
    • Car Tech
    • Business
    • Science & Health
  • Reviews
  • Buying Guides
  • How-to
  • AI
  • Computing
    • Apps
    • Security
    • Gaming
  • More
    • Tools
    • Puzzles
    • Mobile
  • Launchpad
  • Sign in
TechEngage » Security & Privacy

Google pulls down several apps from Play Store for stealing Facebook data

News

Avatar for Sheharyar Ahmad Saeed Sheharyar Ahmad Saeed Connect with Sheharyar Ahmad Saeed on LinkedIn Published: Jul 5, 2021 · 7:12 PM ET Updated: Jul 6, 2021 · 4:12 AM ET

An icon of Android featuring Facebook shortened icon on it
Shares5FacebookTweetPinLinkedInPrint

In response to researchers’ claims that some specific Android apps used a sneaky method to grab users’ Facebook login credentials, Google has recently banned nine apps downloaded more than 5.8 million times from its Playstore.

According to a post published by security firm Dr. Web, the apps provided fully functioning services ranging from photo editing, framing, exercise, and training, to daily horoscopes to win the user’s trust. Furthermore, the junk file removal was from Android devices also functional in these apps in order to minimize the sense of danger on the user’s end. In addition, each of the identified apps offered a way for users to disable in-app ads by logging into their Facebook accounts. The user selected the option, confronted with a Facebook login form that asked for their username and password.

The security firm revealed how these apps exploited the use of Facebook login,

“After receiving the necessary settings from one of the C&C servers upon launch, they loaded the legitimate Facebook web page https://www.facebook.com/login.php into WebView. Next, they loaded JavaScript received from the C&C server into the same WebView. This script was directly used to hijack the entered login credentials.

After that, this JavaScript, using the methods provided through the JavascriptInterface annotation, passed the stolen login and password to the trojan applications, which then transferred the data to the attackers’ C&C server. After the victim logged into their account, the trojans also stole cookies from the current authorization session. Those cookies were also sent to cybercriminals.”

There are five malware variants hidden inside the apps, according to the researchers. In addition to three native Android apps and two cross-platform apps built with Flutter (Google’s cross-platform framework). Despite using different configuration file formats and JavaScript code, Dr. Web said they are all classified as the same trojan because they use the same methods to steal data.

Read more: Google Play Store alternatives

The most popular app was PIP Photo, which was downloaded more than 5.8 million times. Almost 500,000 users downloaded Processing Photo, the app that came next. Here are the rest of the apps:

  • Rubbish Cleaner: with more than 100,000 downloads
  • Inwell Fitness: with more than 100,000 downloads
  • Horoscope Daily: with more than 100,000 downloads
  • App Lock Keep: with more than 50,000 downloads
  • Lockit Master: with more than 5,000 downloads
  • Horoscope Pi: with 1,000 downloads
  • App Lock Manager: with 10 downloads

These apps are no longer available on Google Play. According to a statement to Ars Technica, a Google spokesman said that the company has also banned developers from submitting new apps to the store in the future. Google did the right thing, but it still poses only a small barrier for developers, as they can sign up under the garb of a new name for $25 and set up a new developer account. Downloaded applications should be thoroughly inspected, as well as Facebook accounts, to make sure they are not compromised.

Prior to the removal of these apps, Google had also removed 29 malicious photo editing and beauty apps from its Play Store. The action was also taken place due to the research rendered by the security firm Trend Micro. In 2018, around 500,000 users downloaded malware onto their devices when they attempted to download racing games from the Google Play store. It was found that thirteen apps were infected with malware. The Trending section even listed two of these apps.

Dr. Web suggests that users should only install apps on Android devices from trusted sources and known developers, and the reviews of other users should be considered. Even though reviewers cannot guarantee an app’s safety, one can get a hint of the performance, quality, and sometimes security-related issues, including other insights of that particular app. In addition, users should be aware of when and which apps ask for their account information. It would be better not to proceed and uninstall the suspicious program if they are unsure whether what they are doing is safe.

Something incorrect? Report an error in this article. Include a source if you have one; your name and email are optional.

Filed Under: Security & Privacy, Tech News & Analysis Tagged With: Data breach, Facebook, Google, Google Play Store, News

Related Stories

  • Googlebook Shows How Android 17 And Gemini Intelligence Could Reshape Google’S Ecosystem

    Googlebook Shows How Android 17 and Gemini Intelligence Could Reshape Google’s Ecosystem

    AIMay 16, 2026

  • Openai Pauses Advanced-Model Research After Agent Bypasses Network Restrictions

    OpenAI pauses advanced-model research after agent bypasses network restrictions

    Tech News & AnalysisSep 27, 2026

  • Akamai’s $11.6 Billion Anthropic Cloud Deal: Costs, Timeline And Cpu Strategy

    Akamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategy

    Tech News & AnalysisSep 27, 2026

Stay on top of technology

Get TechEngage reviews, buying guides and news in your feed.

Follow on Google News
Shares5FacebookTweetPinLinkedInPrint
Avatar for Sheharyar Ahmad Saeed

Sheharyar Ahmad Saeed

Mobile & Events Reporter

Sheharyar Ahmad Saeed is a Mobile and Events Reporter at TechEngage who covers smartphone launches, apps, technology conferences, and social media. He has written more than 170 articles, making complex product announcements easy to follow for everyday readers.

Joined TechEngage October 2020First article on TechEngage October 2020

Reader Interactions

Share Your Thoughts Cancel reply

Please read our comment policy before submitting your comment. Your email address will not be used or published anywhere. You will only receive comment notifications if you opt to subscribe below.

Primary Sidebar

Google News

Get TechEngage in your feed

Reviews, news, and buying guides as they publish.

Follow on Google News

Recent Stories

  • Usb C Power Meters Techengage |
    Computing & HardwareBest USB-C Power Meters for Chargers and CablesSep 28, 2026
  • Akamai Anthropic Cloud Techengage |
    Tech News & AnalysisAkamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategySep 27, 2026
  • Openai Agent Dns Incident Techengage |
    Tech News & AnalysisOpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Ai Markets Feat |
    AIThree CEOs Asked to Slow Down. The President Said No and the Market Fell 3 Percent. Hassan Taher on What Actually Happened.Sep 21, 2026
  • Iphone 18 Pro Availability Sept 18 |
    Tech News & AnalysisiPhone 18 Pro and Pro Max Available Today in 65+ CountriesSep 18, 2026

More in Security & Privacy

  • Openai Agent Dns Incident Techengage |
    OpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Photo 2023 05 23 19 03 36 Jpg |
    5 Internet Security Suites to Get For Fortifying Your Internet SecurityMay 24, 2023
  • Google Authenticator Gets Cloud Backup Support Jpg |
    Google Authenticator finally gets most awaited cloud sync featureApr 26, 2023
  • Uk Twitter Accounts Hacked Abdugeek Jpg |
    Twitter’s SMS 2FA is going away today, switch before it’s too lateMar 20, 2023
More Security & Privacy stories →

Footer

Discover

  • About TechEngage
  • Company News & Updates
  • Our Team
  • Advertise
  • Send us a tip
  • Submit your company to TechEngage Launchpad Hot
  • TechEngage Brand Kit
  • Contact us
  • Tools & Calculators

Legal pages

  • Editorial Standards
  • Reviews Policy
  • Our Ethics
  • Corrections Policy
  • Affiliate Disclosure
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • GDPR Compliance
  • Copyright & DMCA

Must reads

  • Best Mechanical Keyboards Under $100
  • Best USB-C Hubs
  • Best Portable SSDs
  • Best Gaming Graphics Cards (GPUs)
  • Best Long-Range Outdoor WiFi Extenders
  • Best Wireless CarPlay Adapters
  • Best Slack Alternatives
  • Best Long-Range Walkie-Talkies

Download our apps

TechEngage app coming soon on App Store

© 2026 TechEngage®. All Rights Reserved. TechEngage® is a project of TechAbout LLC.

TechEngage® is a registered trademark in the United States under Trademark Number 6823709 and in the United Kingdom under Trademark Number UK00003417167. It is also ISSN protected under ISSN 2690-3776 and has OCLC Number 1139335774.

Contact team@techengage.com · WhatsApp +1-307-381-8801

Your analytics choice
Allow Google Analytics to help us understand readership? You can use the site without it and change this choice anytime.

Privacy details