Technique
Malicious App Installation
Also known as: Trojanized Apps, Fake Apps, Rogue Apps, Mobile Banking Trojan, Dropper Apps, Copycat Apps, Sideloaded Malware, PHA (Potentially Harmful Applications)
Tricking victim into installing fake or trojanized mobile apps that steal credentials or financial data.
Common attack flows
How it fits in a scam
This technique shows up duringCOMPROMISE
Defense
How to defend against this
How to spot it
- App requests excessive or unrelated permissions (e.g., calculator asking for SMS access)
- Unknown developer with no history, website, or other apps
- Low download counts or suspiciously few reviews for popular-seeming apps
- Spelling errors in developer name, app description, or UI
- Unexpected battery drain, data usage, or device slowdown after installation
- App prompts for 'update' shortly after installation (dropper behavior)
- Aggressive popup ads appearing outside the app
- App requests Accessibility Services unnecessarily
Further reading