Observed Signal · Jul 5, 2021 · Policy Update · Source: OnlineMarketing.de · Impact: 4/5 · Sentiment: Negative

Google Removes Trojan Android Apps Stealing Facebook Logins

Executive Signal Summary

Google removed nine Android apps from the Play Store after researchers at Dr. Web identified a credential-stealing scheme. The apps, which had more than 5.8 million total downloads, displayed ads and offered to disable them or unlock features if users logged in with Facebook. Users were redirected to the legitimate Facebook login page, but credentials entered there were captured and sent to criminals’ servers. The affected apps included PIP Photo Rubbish Cleaner, Inwell Fitness, Horoscope Daily, App Lock Keep, Lockit Master, Horoscope Pi, App Lock Manager, and Processing Photo, and their developers were also blocked by Google. Google stated that developers must now verify their identity when creating accounts (a $25 fee may apply). Ars Technica reported on the incident. The event underscores ongoing mobile security risks and demonstrates platform-level enforcement against credential-harvesting malware.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Policy update / enforcement by Google (major platform) related to developer identity verification and mobile security.

SIGNAL RADAR

Track APPS Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Dr. Web researchers identified nine apps that harvested Facebook login data.
  • Google removed these apps from the Google Play Store.
  • Total downloads across the apps exceeded 5.8 million.
  • Affecting apps: PIP Photo Rubbish Cleaner, Inwell Fitness, Horoscope Daily, App Lock Keep, Lockit Master, Horoscope Pi, App Lock Manager and Processing Photo.
  • Developers were blocked and must verify their identity when creating new accounts (ID verification).
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: OnlineMarketing.de•Published: Jul 5, 2021
Original Coverage Title: “Rausschmiss: Google entfernt mehrere Trojaner-Apps - | OnlineMarketing.de”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Android mobile malware / security alertMay 8, 2026

New Android Trojans Target Over 800 Apps

Security researchers at Zimperium have identified four new Android trojans — RecruitRat, SaferRat, Astrinox and Massiv — that target banking and social-media applications. The trojans together aim at credentials and transaction theft across more than 800 apps. The malware can actively hide on infected devices (for example by replacing app icons with transparent images), remain dormant to evade initial scans, download additional payloads later, and hide malicious code inside ZIP structures. Researchers observed distribution vectors including fake job portals and illegal streaming sites; one trojan mimics the HR service Hirex. Users are advised to avoid sideloading apps from unknown websites and to use official app stores such as Google Play or trusted alternatives like F‑Droid.

Read assessment
Advertising Quality (Viewability, Brand Safety, Fraud)Feb 26, 2026

Google Eradicates 115 Fraudulent Apps Impacting 25 Million Devices

Google and Integral Ad Science (IAS) disrupted a large Android-based ad-fraud operation called Genisys that used over 115 mobile apps and AI-generated shell websites to generate fraudulent ad traffic across more than 25 million devices. The scheme covertly used in-app browsers to send traffic to nearly 500 AI-generated domains, misrepresented app bundle IDs (including popular app IDs like Netflix and Instagram) to obscure the activity, and produced millions of bid requests that served ads to non-human or low-quality inventory. IAS detected the operation in September 2025 and tracked its peak in December; Google removed the apps from the Play Store and updated protections (Google Play Protect) to disable Genisys-affiliated apps. IAS reports Genisys-related bid requests have fallen by over 95%.

Read assessment
Policy UpdateOct 8, 2026

US Government Excludes Microsoft from Visa Program

The US government has barred Microsoft from participating in the permanent residency process for foreign workers with H-1B visas, accusing the company of abusing the program. Vice President JD Vance stated that Microsoft laid off 6,000 American employees last year while benefiting from 6,300 H-1B visa holders. The Department of Labor, led by Keith Sonderling, will not accept new permanent residency applications from Microsoft, as well as several consulting firms and Adobe. This action comes weeks before the midterm elections and reflects the Trump administration's broader criticism of the H-1B program, which it claims disadvantages American workers. Microsoft has not yet responded. The move could impact the tech industry's ability to retain skilled foreign talent.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.