• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - App found in Google Play Store that steals users’ FB accounts

App found in Google Play Store that steals users’ FB accounts

Claire by Claire
March 22, 2022 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

Recently, security researchers discovered an application in the Google Play Store. It has been installed by more than 100,000 people. It is wrapped in the appearance of a fun photo tool, but it does have hidden evil intentions. It uses a built-in Trojan program to steal the login passwords of the Facebook platform, which currently has a large number of users around the world. However, this application was not reported and removed from the shelves until recently.

App found in Google Play Store that steals users’ FB accounts

This application called “Craftsart Cartoon Photo Tools” boasts that users can upload personal photos and images and convert them into comic-style illustrations through algorithms. In the past week, security research unit Pradeo discovered a Trojan called “FaceStealer” in it. This Trojan will display a Facebook login page when you open the application, requiring users to log in to their personal account before using it.

According to Michal Rajčan, a security researcher at Jamf, when the user enters the login password, the application will send the entered content to Zutuu’s command and control server (C&C server, Command & Control Server), and the purpose of the unscrupulous person is to collect this personal information. In addition to the C&C server, the malicious Android application will link to an external website and send more data to the other end of the website, which has been used in the past to distribute other malicious FaceStealer Android applications.

App first presents screen with Facebook login prompt which redirects to real Facebook login page pic.twitter.com/atUGp2BCfS

— Michal Rajčan (@RajcanMichal) March 16, 2022

as As Pradeo explains in its safety report, the developers and publishers of these apps appear to have automated the repackaging process and injected small pieces of malicious source code into otherwise legitimate apps. This approach helps apps pass the Play Store review process without raising any red flags. Once a user opens it, no functionality is actually available unless they are logged into their Facebook account (and even if you are logged in, there won’t be any functionality available).

Since many apps now require users to log in to a Facebook account when it is clearly unnecessary, users have become numb to these login prompts and enter their personal login information without hesitation. While these photo-processing apps are popular and interesting, people should be careful when installing them and entering sensitive personal information, including biometric data (facial images). These apps can modify and collect images on a remote server rather than on the device, leaving them vulnerable to the risk of being stored indefinitely, shared with others, or resold.

Although this app has been removed from the shelves, there are more potentially risky apps that still exist in the Google Play Store until they are detected to have too many negative reviews or are discovered by security research units. In most cases, you can find out whether the app is a scam or malware by looking at the comments below the Google Play Store app. As you can see below, user reviews for “Craftsart Cartoon Photo Tools” are overwhelmingly negative and it only receives a rating of 1.7 out of 5 stars. Additionally, many of these reviews warn that the app has limited functionality and requires a Facebook login. Secondly, although the developer name of this app is listed as “Google Commerce Ltd” and it looks very much like it was developed by Google, his contact information is a random Gmail email address, which is also a big red flag.

If you have this app installed on your phone, be sure to delete it immediately and reset your Facebook login password. It is best to enable two-factor authentication for additional protection.

Source: KOCPC Chinese

Tags: AndroidappFacebookImage processingmalwareTrojan horse

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology