Rogue app compromises 500,000 Instagram accounts

InstaAgent collected and sent users' unencrypted account details to unknown servers before it was spotted

An app that stole up to half a million Instagram users' account details has been pulled from the Google Play Store and Apple's App Store.

Developer David Layer-Reiss, of Peppersoft Development, discovered that "Who Viewed Your Profile InstaAgent" was collecting login credentials to users' Instagram apps, and sending them, unencrypted, to the developer's server.

Instagram account usernames and passwords were then relayed to unknown servers in plain text, as Layer-Reiss demonstrated with a screen capture shared on Twitter.

It was also responsible for a fair bit of shameless self-promotion, spamming users' Instagram feeds with advertisements for the app without their permission.

He shared his findings in a series of tweets this morning, speculating that the developer had gained access to over 500,000 Instagram accounts.

The free app, which promised users the ability to see who was viewing their Instagram profile, topped the UK and Canadian stores before it was removed earlier today.

A number of apps advertising similar features still exist despite warnings from Instagram to avoid them and attempts to regulate third-party clients.

Apps offering an influx of new followers, claiming to sell likes, or revealing profile viewers generally do not work because information that is not shared with users is not shared with third-party applications, either. In most cases, they simply violate Instagram's terms of service.

To confuse things further, a legitimate app called InstaAgent is available for iOS, this one created by Philadelphia-based developer Craig Pearlman. Pearlman has tweeted about the confusion, attempting to differentiate his app from the information-stealing client making headlines. 

With hundreds of thousands likely affected, anyone who has downloaded the app should consider their Instagram account compromised. Users are advised to remove the app, revoke its access on Instagram, change their password, and monitor their account.

For those who have recycled log-in information for other services, it is best to monitor those accounts and reset those passwords as well - and perhaps not reuse passwords this time.

In the mean time, everyone is left wondering what the developer intended to do with half a million Instagram account details.

An Instagram spokesman told IT Pro"These types of third-party apps violate our platform guidelines and are likely an attempt to get access to a user's accounts in an inappropriate way. We advise against installing third-party apps like these. Anyone who has downloaded this app should delete it and change their password."

Featured Resources

Five lessons learned from the pivot to a distributed workforce

Delivering continuity and scale with a remote work strategy

Download now

Connected experiences in a digital transformation

Enable businesses to meet the demands of the future

Download now

Simplify to secure

Reduce complexity by integrating your security ecosystem

Download now

Enhance the safety and security of your people, assets and operations

Enable a true vision of security with an engineered solution based on hyperconverged and storage platforms

Download now

Recommended

'Largest ever' Magecart hack compromises 2,000 online stores
hacking

'Largest ever' Magecart hack compromises 2,000 online stores

15 Sep 2020
Infocyte integrates with Palo Alto Networks Cortex XSOAR
cyber security

Infocyte integrates with Palo Alto Networks Cortex XSOAR

19 Aug 2020
Andrew Daniels joins Druva as CIO and CISO
Cloud

Andrew Daniels joins Druva as CIO and CISO

22 Jul 2020
University of California gets fleeced by hackers for $1.14 million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020

Most Popular

Accenture ploughs $3 billion into cloud migration support group
digital transformation

Accenture ploughs $3 billion into cloud migration support group

17 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
Google Pixel 4a review: A picture-perfect package
Google Android

Google Pixel 4a review: A picture-perfect package

18 Sep 2020