A malware named Facestealer poses a potential threat to all users of the Google Play Store. The malware in question would even be linked to 200 app seemingly harmless, such as fake VPNs, photo editing tools, and apps related to cryptocurrency mining.
As the name suggests, Facestealer can go as far as stealing all sensitive data of affected users, i.e. names and surnames, contacts, geolocation data and also passwords of social networks.
source: Blogtrepreneur Flickr Photostream, license CC BY 2.0)
L’complete list from the malicious apps is not yet available. For now, the only titles disclosed are the following:
- Daily Fitness OL;
- Enjoy Photo Editor;
- Panorama Camera;
- Photo Gaming Puzzle;
- Swarm Photo;
- Business Meta Manager;
- Cryptomining Farm Your own Coin.
As mentioned, many of these apps are photo editing apps, but there are also some like Cryptomining Farm Your Own Coin where the malware acts in a far more subtle way. Inside, in fact, there is no invitation to fraudulent payment services, but only the invitation to insert one private key when you connect your wallet to the application. Once entered, the key is sent to the server controlled by the attackers without obviously using any encryption.
Photo credit – Trendmicro.com
So how do you defend yourself? The tips are, as usual, avoid downloading apps with few downloads and few reviews, but also apps that offer free functions that usually have to be paid for (the price to pay, in that case, could be your data). Furthermore, it is good to install an antivirus that analyzes all the apps and games as we download them, signaling the presence of any threats before it is too late.
For more information on the malware and the apps found to be infected, you can read the news posted on the research company’s website Trend Micro.