Mobile

12/13/2017
01:30 PM
50%
50%

Google Play Offered Fewer Blacklisted Mobile Apps in Q3

Third-party AndroidAPKDescargar store carried the most blacklisted mobile apps.

Blacklisted mobile apps are on the rise in app stores: a new report shows a 35% increase in the third quarter across 14 different online stores.

According to new data from RiskIQ, blacklisted mobile apps totaled 51,188 in the third quarter.

Mobile apps are submitted to and analyzed by anti-virus vendors when suspected of malicious behavior, says Mike Wyatt, RiskIQ's product operations director. If such activity is detected, anti-virus vendors will block, or blacklist, the apps from downloading and running on a user's device. Every blacklisted app that slips past an app store's vetting process could potentially cause malicious harm to a user's device or data.  

AndroidAPKDescargar, which offers Spanish-language mobile apps, fueled the third quarter jump with 20,907 blacklisted mobile apps – more than double its 9,285 in the prior quarter, the report notes.

Google Play, meanwhile, had fewer blacklisted mobile apps: 8,125 in Q3, down from 8,657 in the previous quarter, according to the report.

But more importantly, notes Wyatt, Google cut the percentage of blacklisted apps in Google Play to 4% of its total 204,981 apps in the third quarter – down from 8% in the previous quarter. "The percentage is a more important figure ... since it indicates how likely the risk is," Wyatt says.

Google Play and Apple's App Store are considered the go-to place for apps by security experts, because both companies vet the apps in their stores. Nonetheless, malware-laden apps have been found in both stores. Android/TrojanDropper.Agent.BKY, for example, was discovered in Google Play.

Although the percentage and total number of blacklisted apps declined in the third quarter, Wyatt notes it is too early to say whether Google Play has improved its security.

"The Google team works hard to ensure bad apps stay out of their store, so they were able to decrease the number in the third quarter. However, we do not see a consistent downward trend, so it remains to be seen if this number will drop again in the fourth quarter," he says.

AndroidAPKDescargar, meanwhile, did not do so well. Nearly a third of its 68,421 apps in the third quarter were blacklisted apps, a similar slice as its second quarter, the report notes. Mobile game app store 9Game.com had the highest penetration of blacklisted apps on its site in the third quarter, 97% of 5,859 apps.

Wyatt advises CISOs and security teams to educate their BYOD workers to use the official app stores and implement tighter security controls for the devices to reduce introducing a security risk.

BYOD and corporate mobile device users should also be advised to be wary of granting apps extensive permissions and also be leery of downloading apps from pages where there are misspellings on the page, says Wyatt.

Related Content:

 

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
How the US Chooses Which Zero-Day Vulnerabilities to Stockpile
Ricardo Arroyo, Senior Technical Product Manager, Watchguard Technologies,  1/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3906
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.
CVE-2019-3907
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).
CVE-2019-3908
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can decrypt them and obtain sensitive data.
CVE-2019-3909
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.
CVE-2019-3910
PUBLISHED: 2019-01-18
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.