Report Shows Increase in Number of Hacked Mobile Apps
The third annual State of Mobile App Security report published by application protection solutions provider Arxan Technologies shows that cybercriminals have created hacked versions of most of the top Android and iOS applications.
According to the report, which is based on the analysis of 360 mobile applications, there are cloned or repackaged versions for 97% of the top 100 paid Android apps, and 87% of the top 100 paid iOS apps. In the case of iOS applications, the number of hacked programs has increased considerably compared to last year (from 56%).
Of the 20 most popular free applications, 80% of those for Android and 75% of those for iOS have been hacked, Arxan said.
When it comes to financial services applications, the study shows that a large percentage of the top 20 apps on each platform have been cloned or repackaged by malicious actors. In the case of Android applications, the percentage of hacked apps increased from 76% to 95% over the past year, while iOS app hacking increased from 30% to 70%.
As far as the top 20 retail applications are concerned, only 35% of iOS apps have been hacked. However, the report shows that 90% of the top Android retail apps have been targeted by cybercriminals.
In the healthcare/medical category, researchers found that 90% of Android apps have been hacked. A worrying fact is that 22% of these applications have been approved by the United States Food and Drug Administration (FDA).
The report also contains a series of recommendations for application developers. Experts advise developers to ensure that applications with high-risk profiles are tamper-resistant and capable of detecting threats at runtime. In the case of payment applications and mobile wallets, they must be protected with app hardening and secure crypto, Arxan said.
The number of free application downloads is expected to reach 253 billion by 2017 so it’s not surprising that malicious actors are increasingly turning their attention to mobile platforms. While Apple’s iOS operating system is considered more secure than Google’s Android, it’s not completely immune to threats. A perfect example is the recently discovered WireLurker malware which is said to have infected hundreds of thousands of devices in China.
“The pursuit of greater mobile application security remains at the forefront our research and development initiatives,” commented Jonathan Carter, technical director at Arxan. “We continue to evolve our security innovations based on emerging threats to ensure the strongest application protection for our customers in the dynamic battlefield against hackers.”
The complete State of the Mobile App Security report is available online. The research was conducted in October 2014 and is based on the analysis of applications found in unofficial app stores, app distribution sites, torrent websites, and file download services.

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- Intel Boasts Attack Surface Reduction With New 13th Gen Core vPro Platform
- Dole Says Employee Information Compromised in Ransomware Attack
- High-Severity Vulnerabilities Found in WellinTech Industrial Data Historian
- CISA Expands Cybersecurity Committee, Updates Baseline Security Goals
- Exploitation of 55 Zero-Day Vulnerabilities Came to Light in 2022: Mandiant
- Organizations Notified of Remotely Exploitable Vulnerabilities in Aveva HMI, SCADA Products
- Waterfall Security, TXOne Networks Launch New OT Security Appliances
- Hitachi Energy Blames Data Breach on Zero-Day as Ransomware Gang Threatens Firm
Latest News
- Intel Co-founder, Philanthropist Gordon Moore Dies at 94
- Google Leads $16 Million Investment in Dope.security
- US Charges 20-Year-Old Head of Hacker Site BreachForums
- Tesla Hacked Twice at Pwn2Own Exploit Contest
- CISA Ships ‘Untitled Goose Tool’ to Hunt for Microsoft Azure Cloud Infections
- Critical WooCommerce Payments Vulnerability Leads to Site Takeover
- PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw
- CISA Gets Proactive With New Pre-Ransomware Alerts
