Google is still racing to pull Android apps that commit major privacy violations. Ars Technica notes that Google has removed nine apps from the Play Store after Dr. Web analysts discovered they were trojans stealing Facebook login details. These weren’t obscure titles — the malware had over 5.8 million combined downloads and posed as easy-to-find titles like “Horoscope Daily” and “Rubbish Cleaner.”
Google told Ars it banned all the app developers from the store, although that might not be much of a deterrent when the perpetrators can likely create new developer accounts. Google may need to screen for the malware itself to keep the attackers out.
The question, of course, is how the apps racked up as many downloads as they did before the takedown. Google’s largely automated screening keeps a lot of malware out of the Play Store, but the subtlety of the technique might have helped the rogue apps slip past these defenses and leave victims unaware that their Facebook data fell into the wrong hands.