Sunday, November 24, 2024
HomeInternet25,936 Malicious Apps Use Facebook APIs to Obtain a Range of Information

25,936 Malicious Apps Use Facebook APIs to Obtain a Range of Information

Published on

25,936 malicious apps currently using facebook login or messaging API, capable of obtaining a range of information from the Facebook profile such as name, location, and email address.

The Cambridge Analytica data-gathering scandal is mainly due to permissions abused by the developers that associated with the Facebook Login feature. 87 Million Facebook Users Affected by the Cambridge Analytica Data Scandal.

After this incident, Facebook has made some import decision and changes in Facebook products Such as Events API, Groups API, Pages API, Facebook Login, and other Functions.

- Advertisement - SIEM as a Service

Also Read Key Elements and Important Steps to General Data Protection Regulation (GDPR)

Trustlook discovered 25,936 malicious apps based on the App Insights that scans for apps around the world and provides 80 pieces of information for each app, including permissions, libraries, risky API calls, network activity, and risk score.

“When people use Facebook Login, they grant the app’s developer a range of information from their Facebook profile. Back in 2015, Facebook also allowed developers to collect some information from the friend networks of people who used Facebook Login.” reads Trustlook statement.

Trustlook Spokesperson told Threatpost that all the 25,936 malicious apps can do the same thing that led to Cambridge Analytica issue. All the identified malicious apps having risk score 7, it might do things like capturing pictures and audio when the app is closed or making an unusually large amount of network calls.

Earlier this week it was reported that Twitter sold data access to the Cambridge University academic who also obtained millions of Facebook Inc.

According to Twitter, “In 2015, GSR(Global Science Research) did have one-time API access to a random sample of public tweets from a five-month period from December 2014 to April 2015.Based on the recent reports, we conducted our own internal review and did not find any access to private data about people who use Twitter.”

“To be fair, Facebook is not the only company with its APIs embedded in malicious applications. Twitter, LinkedIn, Google, and Yahoo offer similar options to developers, and thus their user data faces similar exposure.” reads Trustlook statement.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...

240+ Domains Used By PhaaS Platform ONNX Seized by Microsoft

Microsoft's Digital Crimes Unit (DCU) has disrupted a significant phishing-as-a-service (PhaaS) operation run by...

Russian TAG-110 Hacked 60+ Users With HTML Loaded & Python Backdoor

The Russian threat group TAG-110, linked to BlueDelta (APT28), is actively targeting organizations in...

Earth Kasha Upgraded Their Arsenal With New Tactics To Attack Organizations

Earth Kasha, a threat actor linked to APT10, has expanded its targeting scope to...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Nearest Neighbor Attacks: Russian APT Hack The Target By Exploiting Nearby Wi-Fi Networks

Recent research has revealed that a Russian advanced persistent threat (APT) group, tracked as...

Critical PDF.js & React-PDF Vulnerabilities Threaten Millions Of PDF Users

A new critical vulnerability has been discovered in PDF.js, which could allow a threat...

LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely From Any Browser, Anywhere

LayerX, pioneer of the LayerX Browser Security platform, today announced $24 million in Series...