Cybercriminals are capitalizing on the success of Instagram with a fake version of the app for Android that attempts to wring money from users via fake SMS texts, according to the security site Sophos.
Sophos on Wednesday identified an Instagram clone that appears to be made by Russian cybercriminals. The post warns that if you download Instagram from sites other than Google Play you run the risk of downloading malware, which will send background SMS texts from your Android device.
[More from Mashable: New Site Challenges Instagram Users to Take Their Best Shot]
The post doesn't explain how the criminals make money from the texts, but a popular scam is to send such messages to premium numbers which incur charges on a user's account.
One way to identify if you've downloaded the app is to look for the following photo:
[More from Mashable: Can Instagram’s Mobile-Only Strategy Work for Other Apps?]
According to Sophos, several versions of that picture appear inside the app's .APK file. "Maybe the reason why his picture is included multiple times is to change the fingerprint of the .APK in the hope that rudimentary anti-virus scanners might be fooled into not recognising the malicious package," the author, Graham Cluley, a technology consultant at Sophos, speculates.
An updated version of the post notes that several readers have identified the image as a Russian meme. Here is the full version of the photo:
This story originally published on Mashable here.