Mobile
2/23/2016
04:00 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Leaky Apps Far Riskier Than Mobile Malware

Even top enterprise apps are rampant with data leakage and privacy-invasive behavior.

Mobile malware may be the most intriguing thing to capture the attention of mobile-minded security researchers today. But according to a report out today by Appthority, the bigger risks statistically come from misbehaving legitimate apps.

The Appthority Enterprise Mobile Threat Team's quarterly Mobile Threat Report took a deep dive look into some of the most recent threats on the mobile app landscape. While significant iOS exploits like XcodeGhost, YouMi, and MobiSage certainly raised eyebrows, the researchers found that a risk analysis across the entire app ecosystem showed that these and other malware risks are eclipsed by data leakage and privacy invasive behaviors from otherwise legitimate applications.   

"While Apple and Google generally do a great job of reviewing apps for overall risk, they are mainly trying (sometimes unsuccessfully) to keep malware out of the app stores and are not monitoring apps for other enterprise risks like data exfiltration and privacy invasive behaviors," the report explained.

Some of the data leak behaviors include sending out or broadcasting unique device identifiers, address book, calendar, location or SMS messages, attempting to root a device or capabilities for recording calls, or other user-initiated activity. Privacy invasive activity includes tracking locations, accessing address book, calendar, SMS archives, microphone and other functions, and sending data to ad networks.

In examining over 315,000 unique iOS and Android apps from the respective platform's app stores, Appthority found that just over 48% of iOS apps and nearly 87% of Android apps displayed data leakage behaviors.

Meanwhile over 62% of iOS and 86% of Android apps engage in privacy invasive behavior. Even these behaviors pose risks to enterprises.

"For example, if an app is leaking employee address book data, it will be much easier for attackers to user the information collected from the address book to launch a targeted spear phishing, malware or other cyber attack," the report explains.

Interestingly, enterprise apps are no better in this department--in fact, they're just a tick more risky. Of the 100,000 apps already in enterprise mobile ecosystems or being pre-evaluated for risk to be entered in this enterprise app pool, nearly 50% of iOS apps and over 88% of Android apps display data leakage behaviors, and over 65% of iOS apps and 88% of Android apps engage in privacy invasive behaviors. Narrow that down to the top 150 apps in the enterprise and these numbers go up significantly, by as much as 30 percentage points.

Clearly, enterprises are facing an uphill battle with vetting these applications.

"Even if an enterprise were to focus on trying to whitelist the top 150 most popular apps, each of these apps may see up to 10 new versions per year, creating a bottleneck in the review and approval process," the report says.

 

Interop 2016 Las VegasFind out more about mobile security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.