Pirated mobile Android and Apple apps are getting hacked, cracked and smacked
Network World - Those popular mobile apps that everyone's buying from the official Android and Apple apps stores for business and fun are being torn apart by hackers who turn around and post these abused apps filled with malware, their content pirated or otherwise tampered, according to a study out today.
Security vendor Arxan, which makes tools for hardening applications from tampering, says it wants to make this point about apps abuse with its study that describes how it found that 92% of the top 100 paid apps being sold in the Apple App Store had been hacked in various ways, and so had a full 100% of the top 100 apps originally found in Google Play.
"As a hacker, you can take the official application and make it free, and have hidden malware -- the original app owner doesn't know," says Jukka Alanen, vice president of business development at Arxan Technologies and author of the study, "Mobile Apps under Attack."
Beyond its look to find pirated and malware-laden versions of paid apps, Arxan also says it found that 40% of the top 15 free Apple iOS apps and 80% of the top 15 free Android apps (based on May 2012) were found to be hacked in a similar way.
The hacked apps that Arxan discovered included not just knock-offs of the popular Angry Birds app, but also an app for voice translation, games like Flick Homerun and tools such as Beautiful Widgets from LevelUpStudio.
Alanen says Arxan's research on legit apps that had been pirated and tampered with in some way was done by scouring online resources to find them. For instance, to look for Apple iOS apps, Arxan hunted through the Cydia service which has Cydia software for download that acts as a channel to find both free and paid apps for jailbroken Apple iOS devices.
As a kind of unsanctioned Apple app store, "it's a channel to find these sources," Alanen says. Arxen's hunt for knock-offs of legitimate apps also involved looking around for pirated Android apps, scouring places like iCracker and torrent-based sites. Alanen says there's a problem out there with intellectual property and decompiled apps source code being reused without the owner's permission to create new apps as well, such as versions of games without ads, for instance.
It's all not that hard to do, he asserts. Hackers can "reverse engineer the app" using tools that are freely available online, then tamper with the code, adding features and capabilities, such as video uploads, additional device or operating system support. The hacker can even take stolen code and end up re-publishing it in a different guise to the Apple App Store. Apple does have a process to look for malware, but may not necessarily be sharp in catching pirated code, Alanen says.
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Infographic: Converged Infrastructure Benefits This Infographic quantifies the savings organizations are realizing from increased deployment speed, higher availability, and lower annual costs.
- CIOs Deliver Productivity Breakthroughs with Intelligent Digital Signage Retailers have long recognized the influence that digital signage provides over a shopper's point-of-purchase decision making process.
- Going Paperless? Here's What You Need to Think About As makers of some of the world's most popular PDF solutions, we often consult with businesses & governmental agencies that have the goal...
- The Big Data Opportunity for HR and Finance If CEOs, CFOs, CIOs, and CHROs want to drive their businesses forward, they will need to quickly recognize the enormous value of big...
Enhance Your Virtualization Infrastructure With IBM and Vmware
Date: Wednesday, May 14, 2014, 1:00 PM EDT
Virtualization technology is now expanding beyond the server compute elements to encompass networking and storage...
Transforming Finance, Procurement and Supply Chain Effectiveness with Cross-Functional Analytics
Date: May 6th, 2014
Time: 1 PM EDT
Attend this Webcast to find out how Oracle's packaged analytic applications enable line-of-business managers to examine all...
All Cybercrime and Hacking White Papers |