Mobile

2/23/2016
04:00 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Leaky Apps Far Riskier Than Mobile Malware

Even top enterprise apps are rampant with data leakage and privacy-invasive behavior.

Mobile malware may be the most intriguing thing to capture the attention of mobile-minded security researchers today. But according to a report out today by Appthority, the bigger risks statistically come from misbehaving legitimate apps.

The Appthority Enterprise Mobile Threat Team's quarterly Mobile Threat Report took a deep dive look into some of the most recent threats on the mobile app landscape. While significant iOS exploits like XcodeGhost, YouMi, and MobiSage certainly raised eyebrows, the researchers found that a risk analysis across the entire app ecosystem showed that these and other malware risks are eclipsed by data leakage and privacy invasive behaviors from otherwise legitimate applications.   

"While Apple and Google generally do a great job of reviewing apps for overall risk, they are mainly trying (sometimes unsuccessfully) to keep malware out of the app stores and are not monitoring apps for other enterprise risks like data exfiltration and privacy invasive behaviors," the report explained.

Some of the data leak behaviors include sending out or broadcasting unique device identifiers, address book, calendar, location or SMS messages, attempting to root a device or capabilities for recording calls, or other user-initiated activity. Privacy invasive activity includes tracking locations, accessing address book, calendar, SMS archives, microphone and other functions, and sending data to ad networks.

In examining over 315,000 unique iOS and Android apps from the respective platform's app stores, Appthority found that just over 48% of iOS apps and nearly 87% of Android apps displayed data leakage behaviors.

Meanwhile over 62% of iOS and 86% of Android apps engage in privacy invasive behavior. Even these behaviors pose risks to enterprises.

"For example, if an app is leaking employee address book data, it will be much easier for attackers to user the information collected from the address book to launch a targeted spear phishing, malware or other cyber attack," the report explains.

Interestingly, enterprise apps are no better in this department--in fact, they're just a tick more risky. Of the 100,000 apps already in enterprise mobile ecosystems or being pre-evaluated for risk to be entered in this enterprise app pool, nearly 50% of iOS apps and over 88% of Android apps display data leakage behaviors, and over 65% of iOS apps and 88% of Android apps engage in privacy invasive behaviors. Narrow that down to the top 150 apps in the enterprise and these numbers go up significantly, by as much as 30 percentage points.

Clearly, enterprises are facing an uphill battle with vetting these applications.

"Even if an enterprise were to focus on trying to whitelist the top 150 most popular apps, each of these apps may see up to 10 new versions per year, creating a bottleneck in the review and approval process," the report says.

 

Interop 2016 Las VegasFind out more about mobile security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-6705
PUBLISHED: 2018-12-12
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.
CVE-2018-15717
PUBLISHED: 2018-12-12
Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.
CVE-2018-15718
PUBLISHED: 2018-12-12
Open Dental before version 18.4 transmits the entire user database over the network when a remote unathenticated user accesses the command prompt. This allows the attacker to gain access to usernames, password hashes, privilege levels, and more.
CVE-2018-15719
PUBLISHED: 2018-12-12
Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.
CVE-2018-6704
PUBLISHED: 2018-12-12
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.