External Threat Management

The Q2 2019 Mobile Threat Landscape: Blacklisted Apps Increase 20%, Cyber Attackers Target Tax Season, Surveillance Apps Wreak Havoc

The digital revolution is causing businesses to invest significantly in mobile, where they can make more frequent and more meaningful interactions with employees, prospects, and customers. Global app spending hit $101 billion in 2018 and will surpass that this year. In 2018, global app spending hit $101 billion and is expected to surpass that this year. Mobile is a significant portion of the overall corporate attack surface where security teams often suffer from a lack of visibility.

For the past ten years, RiskIQ's discovery platform has mapped the global mobile threat landscape. It now monitors more than 120 mobile app stores around the world and scans nearly two billion resources daily to look for mobile apps in the wild. With this internet-wide telemetry, RiskIQ observes and categorizes the threat landscape as a user would see it, downloading analyzing, and storing every app we encounter while recording changes and new versions.

In our Q2 2019 Mobile Threat Landscape report, we provide an overview of the Q2 2019 Mobile Threat Landscape and dive into emerging trends you need to know for the rest of the year.

For the second-consecutive quarter, blacklisted apps increased with a 20% spike, increased from 44,850 to 53,955, and accounting for over 2% of all apps in RiskIQ's dataset. Blacklisted apps are apps that appear on at least one blacklist such as VirusTotal, which, per its website, inspects files or web pages with over 70 antivirus products and other tools. A blacklist hit from VirusTotal shows that at least one vendor has flagged the file as suspicious or malicious.

The percentage of blacklisted apps relative to the total number of apps known by RiskIQ also increased for the second-straight quarter, jumping from 1.95% to 2.1 %. These blacklisted apps feature a host of familiar threats such as brand imitation, phishing, and malware. The mobile threat landscape also saw cyber attackers leveraging tax season with malicious and fraudulent apps meant to fool consumers filing their taxes into downloading them.

Additionally, Q2 saw an influx of heavily downloaded Android apps that abuse permissions and contribute to ad fraud, as well as the emergence of a sophisticated spy app dubbed Exodus that can access sensitive data such as pictures and contacts. Initially designed for Android, the app made its way to the Apple App Store.

Q2 2019 key findings include:

  • Despite the 20% increase in blacklisted apps in Q2, the number of blacklisted apps in the Google Play Store decreased by a dramatic 59%.
  • The percentage of Blacklisted apps relative to the total number of apps known by RiskIQ also increased for the second-straight quarter, jumping from 1.95% to 2.1%.
  • RiskIQ detected 2,554,616 apps, a nearly 11% increase in app downloads from Q1.
  • Feral apps proved to be exceptionally dangerous, with a 51% blacklist rate.
  • Our research found 4,162,450 total apps matching tax-branded key terms in app stores around the world, with 30% of them, 1,221,070, blacklisted.

This quarter's report goes on to offer tips, including that users should be skeptical when downloading mobile apps and have antivirus software along with regular backups. Malicious apps mimicking popular, highly downloaded apps is a persistent problem. These tactics are successful because we recognize and make instantaneous judgments about visual stimuli.

Download the RiskIQ Mobile Threat Landscape Q2 2019 report here.

Subscribe to Our Newsletter

Subscribe to the RiskIQ newsletter to stay up-to-date on our latest content, headlines, research, events, and more.

Base Editor