InstAgent app
Intrusive InstAgent app sends Instagram usernames and passwords to unknown server Twitter/peppersoftDev

An Instagram app – InstaAgent – has been flagged after a developer found it stores user names and passwords of Instagram users and sends them to an unknown server. This app basically keeps track of people visiting a user's profile.

The app's intrusive features were discovered by a Peppersoft developer who runs the Twitter handle peppersoftDev. The developer said the app -- whose full name is "Who Viewed Your Profile-InstaAgent" -- sends users' passwords and usernames in clear text to a server called instagram.zunamedia.com. InstaAgent has even been posting photos without a user's permission in his or her Instagram profile. This is because InstAgent has access to a user's credential and can log in to their Instagram accounts.

**Top news**
"Who Viewed Your Profile - InstaAgent" (iPhone) STEALS you Instagram password !
DO NOT USE THIS APP !https://t.co/syz88fH7hv

— David Layer-Reiss (@PeppersoftDev) November 10, 2015

"Who Viewed Your Profile" #Instaagent will send your Instagram Username and Password to an unknown server! pic.twitter.com/8uZJljJdtO

— David Layer-Reiss (@PeppersoftDev) November 10, 2015

"InstaAgent" - very strange things are happening. The username password is sent in CLEARTEXT to the uknown servers!

— David Layer-Reiss (@PeppersoftDev) November 10, 2015

Surprise, surprise , #InstaAgent is also posting images without you permission in your #Instagram profile 😂 . pic.twitter.com/Syvsv71wcn

— David Layer-Reiss (@PeppersoftDev) November 10, 2015

Quite a popular app, InstAgent is the first malware in the iOS App Store that has been downloaded half a million times, said peppersoftDev. Besides being popular in the US, InstAgent is one of the top apps in both UK and Canada with thousands of downloads. As for its Android version, the app had between 100,000 to 500,000 users, with installations matching iOS.

Following the discovery of the malware, Apple has removed it from the App Store. Even its Android version has been taken down from the Google Play Store.

What should you do?

Those who are currently running the app are advised to delete it as well as consider changing their Instagram passwords. Also, if you are using the similar Instagram password for other accounts, it is recommended you change them as well. As a safety measure you can use any password management app which generates unique passwords for you.

Instagram has previously warned users not to allow access to third-party apps that do not follow its guidelines, and are likely to get access to a user's account in an unauthorised manner. There are dozens of third-party apps that provide Instagram users with followers. Try and avoid such apps.