Photo: Lionel Bonaventure (Getty Images)Google has kicked nine Android apps with more than 5.8 million combined downloads off its Play Store after researchers discovered they contained malicious code used to steal users’ Facebook login credentials, according to the Russian anti-virus software firm Dr. Web.As reported by Ars Technica, these trojan apps were designed to look and function like legitimate services for photo editing, exercising, clearing up storage space on your device, and providing daily horoscopes, Dr. Web’s malware analysts said in a post this week. In reality, this was all elaborate front to trick users into sharing their Facebook usernames and passwords.Here’s how the scheme worked: Each offered users an option to unlock all the apps’ functions and get rid of in-app ads by logging into their Facebook accounts, which likely wouldn’t raise too many eyebrows since a lot of mobile services let you sync your social media accounts. Upon choosing this option, the apps would then load a legitimate Facebook login page containing fields for entering usernames and passwords. Whatever users typed into these forms would go directly to a computer controlled by the hackers, called a command-and-control server, via some cleverly concealed malicious code, Dr. Web researchers wrote: These…
Read More












