Multiple malicious Android apps distributed through Google Play were identified stealing Facebook credentials and session data from users. Researchers linked the activity to the Facestealer malware family and said the apps presented Facebook’s legitimate login page inside an Android WebView, where injected JavaScript captured usernames, passwords, user-agent strings, and cookies before sending the data to attacker-controlled infrastructure. One analyzed sample, com.friendtrip.smartscanner, contacted webtrace[.]club for configuration data and exfiltrated stolen information to an API endpoint on the same domain.
The campaign highlights a broader wave of Android applications built to harvest Facebook logins, with multiple Facestealer-tagged packages reportedly discovered and later removed from the Play Store. Security reporting warned users to stay alert for Facebook credential-stealing apps on Android, as the malware’s use of legitimate-looking login flows and stolen session artifacts could enable account takeover even beyond simple password theft.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported a cluster of more than 40 fake cryptocurrency miner apps on Google Play, including Cryptomining Farm Your own Coin, that tricked users into entering wallet private keys and mnemonic phrases. The apps acted as wrappers for fraudulent mining websites, and researchers found the secrets were transmitted in plaintext to attacker-controlled servers; Google had removed the cited app by the time of writing.
Pradeo reported that the Google Play app Craftsart Cartoon Photo Tools was trojanized with Facestealer and had been installed more than 100,000 times. The app masqueraded as a photo editor, redirected users to a legitimate Facebook login page, and used injected JavaScript to steal credentials and Facebook account data; Pradeo said it alerted Google, but the app was still available as of Monday.
Analysis of the sample com.friendtrip.smartscanner showed it loaded Facebook's legitimate login page in an Android WebView, injected malicious JavaScript, captured usernames, passwords, user-agent strings, and cookies, then contacted webtrace[.]club for configuration and exfiltration.
A cluster of Android applications associated with the Facestealer malware family was identified on Google Play. The apps were designed to steal Facebook credentials and related session data, and the article states they have since been removed from the store.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
blog.pradeo.com
Open sourcetrendmicro.com
Open sourcethreatpost.com
Open sourceblogs.quickheal.com
Open sourcelabs.k7computing.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.