Chevron icon It indicates an expandable section or menu, or sometimes previous / next navigation options. HOMEPAGE

A popular app that promised to show you who viewed your Instagram account may have been stealing passwords

screen1136x1136
Screenshot

The app InstaAgent claimed to offer an appealing use case: the ability to see who views your Instagram profile.

Advertisement

It also may have been harvesting the passwords of thousands of Instagram users and posting photos to their accounts without their knowledge.

The potential malware in the app, which has been removed from Apple's App Store and the Google Play Store, was first discovered by a developer for the German app company Peppersoft.

By asking users to enter their Instagram logins, "Who Viewed Your Profile - InstaAgent" was collecting passwords tied to Instagram accounts and silently posting photos to comprised accounts in an effort to drive more downloads, Peppersoft's developer claimed in a series of tweets:

It's unclear exactly how many people downloaded InstaAgent, but according to the analytics firm App Annie, it did reach the top spot in the App Store's free chart in 15 countries, including the UK and Canada.

Advertisement

"These types of third-party apps violate our platform guidelines and are likely an attempt to get access to a user's accounts in an inappropriate way," an Instagram spokesperson told Tech Insider. "We advise against installing third-party apps like these. Anyone who has downloaded this app should delete it and change their password."

It is unclear who made the InstaAgent app.

Instagram
Advertisement
Close icon Two crossed lines that form an 'X'. It indicates a way to close an interaction, or dismiss a notification.

Jump to

  1. Main content
  2. Search
  3. Account