logo

Instagram credentials Stealer: Disguised as Mod App

ID: e6ebd464-4c13-5056-99f3-6fbc8a28f780

STIX ID: report--e6ebd464-4c13-5056-99f3-6fbc8a28f780

Feed Name: McAfee Labs Blog

Threat Score
55/100

Date Published: 2022-06-10

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research describes an Android credential-stealing malware that masquerades as the Instander Instagram mod to trick users into entering credentials, then exfiltrates those credentials by abusing Firebase's createUserWithEmailAndPassword API (combining user input with a static domain and password) and sending data in Protobuf format to www.googleapis.com; the report includes behavioral analysis, network observations, and an SHA256 sample identified as Android/InstaStealer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.