Updated: August 5, 2026
Mobile apps are a big deal —for consumers, brands, and developers alike. In 2025, consumers spent 5.3 trillion hours using mobile apps across categories ranging from social media and entertainment to business, productivity, and banking. Global consumer spending across mobile apps also reached $167 billion.
The two most prominent platforms, Apple iOS and Google Android, account for the vast majority of the mobile operating system market. In 2025, Apple’s App Store ecosystem facilitated more than $1.4 trillion in billings and sales. Google Play Protect now scans more than 350 billion Android apps daily.
Like desktop applications, there are serious cyber threats that impact mobile apps. Both iOS and Android can and do contain malware, and there are hundreds of third-party app stores that offer potentially unauthorized, often modified, copies of legitimate apps. Even official stores face attempted abuse. In 2025, Apple rejected more than 2 million problematic app submissions, while Google prevented more than 1.75 million policy-violating apps from being published and banned over 80,000 bad developer accounts.
For organizations whose mobile apps are impersonated, the damage to their reputation through the fraudulent use of their app, logos, and branding can be significant. It’s more important than ever that consumers can trust the apps they rely on and that brand owners are confident that their organization’s apps and brand aren’t exploited and impersonated by cyber-criminals.
In this guide, we’ll:
Examine the threat that fake apps pose for both brand owners and consumers
Analyze some high-profile case studies to illustrate how fake apps are used to carry out cyber-attacks
Illustrate how Netcraft’s digital risk protection platform detects, blocks, and takes down fake apps and the mechanisms used to promote them, such as phishing and fake ads
What are fake apps?
A mobile application, or app, is a program that users can install on their device. Often associated with a well-known organization, apps can offer a wile range of functionality covering banking, social media, investing, news, gaming, and more.
Most users obtain apps through Apple’s App Store or Google Play. Android also supports third-party app stores and the direct installation, or sideloading, of apps downloaded from the internet. Apple permits alternative app distribution in the European Union, Japan, and Brazil, although the available options vary by region and may include alternative app marketplaces or downloading apps directly from a developer’s website.
Fake apps, found in both official and third-party Android and iOS stores, are unauthorized copies created by cyber-criminals, which mimic the logo, branding, and functionality of legitimate applications (like the fake banking app shown in the figure below), often with nefarious intentions, such as credential stealing, theft, or system access.
When apps are installed, users can grant permission for them to access other information on the device. While legitimate organizations will have technologies and processes to look after this information, cyber-criminals have no such obligation or intent. This means once a fake app has been installed, it may have access to sensitive data if the user grants permission under the mistaken assumption that a legitimate organization operates it.
In addition to accessing sensitive information acquired “with permission” under false pretenses, fake apps can also install malware onto the device, designed to exfiltrate data, damage the device, or overlay fake pages over real applications to steal sensitive data.

Figure 1 A fake banking app (left) available to download on a third-party app store, and the genuine app available on the Google Play store.
How are fake apps distributed?
Fake apps are found in both official app stores (Apple App Store and Google Play Store) and third-party app stores, with third-party stores posing a higher risk due to less robust vetting processes.
Non-Google-manufactured Android devices often come with an app store operated by the original equipment manufacturer (OEM) pre-installed, such as the Samsung Galaxy Store for Samsung Galaxy devices or the Huawei AppGallery.
Uploading an app to either Google Play Store or the Apple App Store requires submitting it for vetting, so operators can check they are safe to use. This “walled garden” approach means that users can expect a safe experience with apps available in official stores.
Nevertheless, despite these vetting processes, malware continues to make it into stores. In 2020, Google reported that the Joker malware had infected many apps in its official Play store, while the XcodeGhost malware infected apps available from iOS App Store, which could have affected the 100 million users who downloaded compromised apps.
Third-party app stores
Today, the Android platform allows for third-party app stores, and iOS will soon follow in a more limited way in response to recent EU regulations. These are app stores that users must download or access separately, typically characterized by their focus on freedom (as opposed to the safety and privacy of users). While there are fewer people using third-party app stores in comparison to the official app stores, a lack of robust vetting processes means that users who download apps from third-party app stores are more likely to be downloading fraudulent and malicious apps.
Hundreds of third-party app stores claim to offer copies of legitimate Android apps; searching the web for the app’s name demonstrates the sheer number of unauthorized app stores. These copies can be benign (but still are unauthorized by the brand owners) or genuinely dangerous and may include malware or other unwanted software that the user unwittingly installs on their phone.
Even if unmodified, applications available on third-party stores can offer versions with known security vulnerabilities or offer retired functionality.
Doctored apps can also be modified to insert adware which flood the unsuspecting user with hundreds of pop-up ads – many of which will be fake – to gain access to lucrative advertising revenue.
Experiences such as these result in damage and deterioration of trust and brand reputation to legitimate brand owners. No brand owner wants their product available in uncontrolled app stores, potentially tainted with adware, malware or other unwanted behavior.
Case study: Mobile app impersonation on Android
One of the most notorious Android viruses in recent years, FluBot, was able to spread around the world as Android users believed they were installing legitimate versions of popular apps, including parcel-tracking apps and a variety of banking apps (including Great Southern Bank, Suncorp and Ubank).

Figure 2 Fake versions of legitimate banking apps, sent by cyber-criminals to victim’s phones and designed to collect their login and password details
The victims were tricked into unwittingly installing malware that overlayed fake login forms on top of real applications to steal user details. This deception was initiated by sending users “missed parcel” phishing messages, usually by SMS, which contained links to malicious websites that encourage victims to install the fake app.

Figure 3 Examples of scam websites and messages, which contain links to fake apps that contain the FluBot malware.
The FluBot malware accessed the user’s contact list on infected devices and sent scam SMS messages to these numbers as well, thus helping the malware to spread across the world.
Rogue apps: a growing menace
The threat from fake apps is real and growing, so much so that the UK government introduced a voluntary Code of Practice for App Store Operators and App Developers aimed at protecting consumers (and, by extension, the brands that downloaded rogue apps are impersonating) from cyber-criminals and malicious apps.
As the code of practice makes clear, most consumers:
Have no way of knowing whether an app is secure
Will not understand how their data is handled
Implicitly trust apps that they believe they are downloading from established organizations
For all these reasons, rogue apps are an ideal ‘attack vector’ for cyber-criminals; not only does the malicious app, once installed on the consumer’s device, provide access to the vast amounts of personal data that it contains, but the consumer may not even be aware that their device is compromised.
How to protect your brand from fake apps
Protecting your brand from fake apps requires continuous monitoring across app stores and marketplaces, typically achieved through a brand protection solution that includes mobile app protection. When a fake app is identified, the solution gathers evidence and works closely with the app store, marketplace, hosting provider or other infrastructure involved to quickly take down the rogue app.
Fake app detection and takedown from Netcraft
Netcraft searches official and unofficial third-party app stores to find fake apps that impersonate your business’s legitimate applications. As previously mentioned, these fake apps may contain malware or be constructed to trick victims into gaining access to personal information, such as banking details, login details, and passwords.
Where app stores offer applications specific to a country, Netcraft will also run country-specific searches based on where you have a presence.
Apps impersonating your company (and unauthorized copies of your own apps in third-party stores) will be reported to the Netcraft takedown service. Netcraft can also search for and take down unauthorized copies of apps that misuse your trademarks, logos, and branding to defend your reputation and to protect your customers from potential malware.
Typically, the third-party app stores will respond positively to Netcraft’s takedown requests to remove applications that have been uploaded without permission.
Netcraft has spent decades at the heart of the internet ecosystem. We capitalize on our long-standing relationships within the infrastructure community to quickly mitigate the harmful impact of cyber-attacks. As a result of our extensive experience in the industry, in many cases, we have a direct reporting process for immediate takedown of these fake applications.
How users can protect themselves from fake apps
Malicious fake apps (like FluBot) can spread through SMS messages, which usually purport to be from a legitimate organization and contain a link to a ‘lure page’ that attempts to trick victims into downloading and installing the malware. Android and iOS users can protect themselves by using Netcraft’s mobile phishing protection app, which blocks lure pages (and other malicious sites) that host fake apps. This prevents users from being tricked into downloading and installing fake apps in the first place.

Once blocked, users of the Netcraft apps and extensions are immediately protected. Netcraft also licenses its feeds to browsers and antivirus companies along with internet infrastructure companies, protecting billions of internet users from being exposed to fake apps exploiting your reputation.
The Netcraft difference
Netcraft’s automated brand protection platform operates around the clock to detect cyber threats, including fake apps, phishing attacks, and social media impersonation, as well as more than 100 additional attack types. Detected threats are analyzed using our automated threat intelligence platform, and those targeting customers begin the disruption and takedown process.
We are the world’s largest takedown provider and centrally positioned in the global fight against cybercrime. Our detection, disruption, and takedown solutions are highly automated, powered by the vast amounts of data we collect daily, and backed by the expertise of our in-house team. A unique combination of cutting-edge automation, unmatched scale, and a reputation for excellence and transparency built over decades of work—all powered by a passion to make the digital world a safer place—gives Netcraft’s solution an edge that cannot be replicated.
About Netcraft
Netcraft — the global leader in cybercrime detection and disruption — is a trusted partner for three of the four largest companies in the world, twelve of the fifty biggest banks, and five of the leading governments in the world. Our comprehensive threat feeds, early fraud detection capabilities, and swift automated countermeasures are unparalleled in the industry.
We perform takedowns for nearly one-third of the world’s phishing sites, blocking close to 170 million malicious sites and counting. Many of the largest brands and organizations around the world trust Netcraft. Our customer base includes a diverse mix of industries, sizes, and organizational types, including leading companies within the financial, retail, and technology sectors.
Find out more
Netcraft’s mission is to detect and disrupt cybercrime at scale through constant innovation, extensive automation, and unique insight, delivering a safer online experience for everyone. To find out how Netcraft’s cybercrime detection, disruption, and takedown platform can protect your organization from the threat of fake apps, you can request a demo by visiting https://www.netcraft.com/book-a-demo/, or find out more by visiting our Mobile App Protection page.






