Android/Trojan.Spy.FakeInsta

ThreatDown is now the name of the Malwarebytes line of business products. References to Malwarebytes below reflect the amazing technology used to first identify the threat.

Short bio

Android/Trojan.Spy.FakeInsta is Malwarebytes’ detection name for a Trojan targeting Iranian Instagram users.

Type of infection

Android/Trojan.Spy.FakeInsta is an app that claims to boost your likes and increase your followers on Instagram. Android/Trojan.Spy.FakeInsta was available in the Google Play app store.

Malicious behavior

After install, the app opens to a splash page, and then a page asking for Instagram credentials. When entered these credentials are then sent to the threat actors’ server.

Aftermath

When your login credentials for a social media account have been stolen this can have serious consequences. It gives threat actors a base from which to gather more information.

Protection

Malwarebytes for Android protects against Android/Trojan.Spy.FakeInsta.

Home remediation

These apps can be uninstalled using the mobile devices uninstall functionality, but these apps can be made available under another name. That is where Malwarebytes for Android can help you, by identifying these apps and removing them.