Instagram Credentials Stealers: Free Followers or Free Likes

Authored by Dexter Shin


Instagram has become a platform with over a billion monthly active users. Many of Instagram’s users are looking to increase their follower numbers, as this has become a symbol of a person’s popularity.  Instagram’s large user base has not gone unnoticed to cybercriminals. McAfee’s Mobile Research Team recently found new Android malware disguised in an app to increase Instagram followers


How can you increase your followers or likes


You can easily find apps on the internet that increase the number of Instagram followers. Some of these apps require both a user account and a password. Other types of apps only need the user to input their user account. But are these apps safe to use?



Figure 1. Suspicious apps in Google Images


Many YouTubers explain how to use these apps with tutorial videos. They log into the app with their own account and show that the number of followers is increasing. Among the many videos, the domain that appears repeatedly was identified


The way the domain introduces is very simple.


Log in with user account and password.
Check credentials via Instagram API.
After logging in, the user can enjoy many features provided by the app. (free followers, free likes, unlimited comments, etc.)
In the case of free followers, the user needs to input how many followers they want to gain.


Figure 2. A screenshot to increase the number of followers by entering in 20 followers.


When you run the function, you can see that the number of followers increases every few seconds.



Figure 3. New follower notifications appear in the feed.


How does this malware spread?


Some Telegram ..

Support the originator by clicking the read the rest link below.