Mobile

12/13/2017
01:30 PM
50%
50%

Google Play Offered Fewer Blacklisted Mobile Apps in Q3

Third-party AndroidAPKDescargar store carried the most blacklisted mobile apps.

Blacklisted mobile apps are on the rise in app stores: a new report shows a 35% increase in the third quarter across 14 different online stores.

According to new data from RiskIQ, blacklisted mobile apps totaled 51,188 in the third quarter.

Mobile apps are submitted to and analyzed by anti-virus vendors when suspected of malicious behavior, says Mike Wyatt, RiskIQ's product operations director. If such activity is detected, anti-virus vendors will block, or blacklist, the apps from downloading and running on a user's device. Every blacklisted app that slips past an app store's vetting process could potentially cause malicious harm to a user's device or data.  

AndroidAPKDescargar, which offers Spanish-language mobile apps, fueled the third quarter jump with 20,907 blacklisted mobile apps – more than double its 9,285 in the prior quarter, the report notes.

Google Play, meanwhile, had fewer blacklisted mobile apps: 8,125 in Q3, down from 8,657 in the previous quarter, according to the report.

But more importantly, notes Wyatt, Google cut the percentage of blacklisted apps in Google Play to 4% of its total 204,981 apps in the third quarter – down from 8% in the previous quarter. "The percentage is a more important figure ... since it indicates how likely the risk is," Wyatt says.

Google Play and Apple's App Store are considered the go-to place for apps by security experts, because both companies vet the apps in their stores. Nonetheless, malware-laden apps have been found in both stores. Android/TrojanDropper.Agent.BKY, for example, was discovered in Google Play.

Although the percentage and total number of blacklisted apps declined in the third quarter, Wyatt notes it is too early to say whether Google Play has improved its security.

"The Google team works hard to ensure bad apps stay out of their store, so they were able to decrease the number in the third quarter. However, we do not see a consistent downward trend, so it remains to be seen if this number will drop again in the fourth quarter," he says.

AndroidAPKDescargar, meanwhile, did not do so well. Nearly a third of its 68,421 apps in the third quarter were blacklisted apps, a similar slice as its second quarter, the report notes. Mobile game app store 9Game.com had the highest penetration of blacklisted apps on its site in the third quarter, 97% of 5,859 apps.

Wyatt advises CISOs and security teams to educate their BYOD workers to use the official app stores and implement tighter security controls for the devices to reduce introducing a security risk.

BYOD and corporate mobile device users should also be advised to be wary of granting apps extensive permissions and also be leery of downloading apps from pages where there are misspellings on the page, says Wyatt.

Related Content:

 

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
The Fundamental Flaw in Security Awareness Programs
Ira Winkler, CISSP, President, Secure Mentem,  7/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14492
PUBLISHED: 2018-07-21
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
CVE-2018-3770
PUBLISHED: 2018-07-20
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
CVE-2018-3771
PUBLISHED: 2018-07-20
An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.
CVE-2018-5065
PUBLISHED: 2018-07-20
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CVE-2018-5066
PUBLISHED: 2018-07-20
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.