• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Malicious App Installation

Also known as: Trojanized Apps, Fake Apps, Rogue Apps, Mobile Banking Trojan, Dropper Apps, Copycat Apps, Sideloaded Malware, PHA (Potentially Harmful Applications)

COMPROMISEMITRE ATT&CK: Masquerade as Legitimate Application (mobile)

Tricking victim into installing fake or trojanized mobile apps that steal credentials or financial data.

Common attack flows

How it fits in a scam

This technique shows up duringCOMPROMISE

Before

  • SmishingDELIVERY
  • QuishingDELIVERY
  • Supply Chain CompromiseCOMPROMISE
  • MalvertisingDELIVERY

After

  • Credential TheftCOMPROMISE
  • Account TakeoverEXPLOITATION
  • Overlay AttackCOMPROMISE
  • MalwareCOMPROMISE
  • +1 more

Defense

How to defend against this

How to spot it

  • App requests excessive or unrelated permissions (e.g., calculator asking for SMS access)
  • Unknown developer with no history, website, or other apps
  • Low download counts or suspiciously few reviews for popular-seeming apps
  • Spelling errors in developer name, app description, or UI
  • Unexpected battery drain, data usage, or device slowdown after installation
  • App prompts for 'update' shortly after installation (dropper behavior)
  • Aggressive popup ads appearing outside the app
  • App requests Accessibility Services unnecessarily

Tools you can use

  • Antivirus SoftwareCost low · Effect medium
  • Mobile Security AppCost low · Effect high

Steps you can take

  • Official App Store OnlyCost low · Effect medium
  • App Permission ReviewCost low · Effect medium

Further reading

  • MITRE ATT&CK

    Masquerade as Legitimate Application (mobile)

  • MITRE ATT&CK

    Deliver Malicious App via Authorized App Store

  • ThreatFabric

    Anatsa banking trojan campaign analysis (2023-2024)

  • Cleafy Labs

    TeaBot banking trojan technical analysis

  • Kaspersky

    Mobile malware overview and types

Related techniques

Same stage

  • Credential Theft
  • SIM Swap
  • MFA Fatigue Attack
  • Clipboard Hijacking
  • Overlay Attack
  • +9 more

Similar defense

  • Remote Access Tool
  • Tech Support Scam
  • Malvertising
  • Smishing
  • Poisoned Software
  • +10 more