Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Meta Warns of Password Stealing Phone Apps

Meta warned a million Facebook users Friday that they have been “exposed” to seemingly innocuous smartphone applications designed to steal passwords to the social network.

Meta warned a million Facebook users Friday that they have been “exposed” to seemingly innocuous smartphone applications designed to steal passwords to the social network.

So far this year, Meta has identified more than 400 “malicious” apps tailored for smartphones powered by Apple or Android software and available at the Apple and Google app stores, director of threat disruption David Agranovich said during a briefing.

“These apps were listed on the Google Play Store and Apple’s App Store and disguised as photo editors, games, VPN services, business apps and other utilities to trick people into downloading them,” Meta said in a blog post.

The apps often ask people to login with their Facebook account information to use promised features, stealing usernames and passwords if entered, according to Meta’s security team.

“They are just trying to trick people into entering in their login information in a way that enables hackers to access their accounts,” Agranovich said of the apps.

“We will notify one million users that they may have been exposed to these applications; that is not to say they have been compromised.”

Advertisement. Scroll to continue reading.

More than 40 percent of the apps Meta listed involved ways to edit or manipulate images, and some were as seemingly simple as using smartphones as flashlights.

“Our sense is these types of malicious app developers try to target multiple services,” Agranovich said, noting the app creators are likely after passwords to more than just Facebook accounts.

“The targeting here seemed to be relatively indiscriminate — get people to download the applications around the world in an attempt to get access to as many login credentials as possible.”

Meta said that it shared what it discovered with Apple and Google, who control what is offered at their respective app shops and each vet offerings.

Apple did not respond to questions regarding whether it took action against any of the apps Meta deemed malicious.

But Google said that most of the apps Meta flagged had already been identified and removed from the Play store by its own vetting systems.

“All of the apps identified in the report are no longer available on Google Play,” a spokesperson told AFP.

“Users are also protected by Google Play Protect, which blocks these apps on Android.”

Written By

AFP 2023

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.