{"id":6753,"date":"2023-06-06T14:00:00","date_gmt":"2023-06-06T11:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/2023\/06\/06\/7-tips-for-spotting-a-fake-mobile-app\/"},"modified":"2026-06-14T10:25:59","modified_gmt":"2026-06-14T07:25:59","slug":"7-tips-for-spotting-a-fake-mobile-app","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/ru\/2023\/06\/06\/7-tips-for-spotting-a-fake-mobile-app\/","title":{"rendered":"7 tips for spotting a fake mobile app"},"content":{"rendered":"<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>You\u2019ve just downloaded a new mobile game, cryptocurrency wallet, or fitness app, but something isn\u2019t right. Your phone\u2019s screen is swamped by annoying ads, the app is not doing what you would expect it do, and, God forbid, you found an unauthorized transaction on your bank account.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Chances are good that the app you downloaded has been after your money or sensitive information.&nbsp;Given the wealth of data we access via our smartphones, it\u2019s little wonder that cybercriminals have their sights on these devices, with threats looming large especially in third-party app stores.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>According to the&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2023\/02\/08\/eset-threat-report-t3-2022\/\" target=\"_blank\" rel=\"noreferrer noopener\">ESET Threat Report T3 2022<\/a>, the number of Android threats soared by 57% in the last few months of 2022, having been driven by a whopping 163% increase in adware and growth of 83% in HiddenApps detections,<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Luckily, you can avoid both malware and potentially unwanted applications (PUAs) by being cautious and doing your diligence. Our tips below will help you to spot a potentially dodgy app from miles away, as well as get your phone back into shape if you downloaded such an app.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2 class=\"wp-block-heading\">How to recognize a fake app<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Check the numbers<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Say you\u2019re looking for what you would reasonably expect to be an app with hundreds of millions of users but only come across an app that, while sounding like the real thing, hasn\u2019t racked up nowhere near as many downloads. If that\u2019s the case, chances are high you\u2019re dealing with an imposter app.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Indeed, be cautious whenever you\u2019re looking to download an app that has been the talk of the town lately. Cybercriminals are always eager to piggyback off a surge in the popularity of an app or service in order to push copycat apps to the market. One recent example is a slew of sketchy&nbsp;<a href=\"https:\/\/www.helpnetsecurity.com\/2023\/05\/17\/fake-chatgpt-apps-google-play-apple-app-store\/\" target=\"_blank\" rel=\"noreferrer noopener\">apps that attempt to ride the ChatGPT craze<\/a>&nbsp;and that were rolled out even before the official app was released.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Much the same applies to bogus updates for legitimate and widely-used apps. One example is the curious case of&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2021\/04\/20\/whatsapp-pink-watch-out-fake-update\/\" target=\"_blank\" rel=\"noreferrer noopener\">WhatsApp Pink<\/a>, a fake color theme for WhatsApp that was peddled via messages on the app in 2021.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Read the reviews<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>If an app is rated poorly, you should probably give it a pass.&nbsp;On the other hand, tons of glowing reviews that all sound almost the same should also raise eyebrows. This is especially the case with apps that have not been downloaded millions of times \u2013 many of those recommendations may be the work of fake reviewers or even bots.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Check the visuals<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Something about the app\u2019s color or logo used doesn\u2019t feel right \u2026 If you\u2019re in doubt, compare the visuals to those on the website of the service provider. Malicious apps often their mimic legitimate counterparts and use similar, but not necessarily identical, logos.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/fake-msqrd-app.png\" alt=\"\" width=\"559\" height=\"423\"><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><em>The impostor is on the right (source:&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2016\/08\/03\/fake-prisma-apps-found-google-play\/\" target=\"_blank\" rel=\"noreferrer noopener\">ESET Research<\/a>)<\/em><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>However, don\u2019t be lulled into a false sense of security just because you recognized the logo of a well-known bank, payment processor or cryptocurrency wallet. Some apps not only misuse the name of a legit service, but are also distributed via websites that are the&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2022\/04\/06\/fake-eshops-prowl-banking-credentials-android-malware\/\">spitting images of the legitimate sites<\/a>. Keep your eyes peeled for details \u2013 a closer look, including at the URLs, often reveals some giveaways.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:image {\"linkDestination\":\"custom\"} \u2013><\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/web-assets.esetstatic.com\/wls\/2022\/04\/Figure-2a.-PetsMore-legitimate-website-on-the-left-copycat-on-the-right.png\" target=\"_blank\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2022\/04\/Figure-2a.-PetsMore-legitimate-website-on-the-left-copycat-on-the-right.png\" alt=\"Figure-2a.-PetsMore-legitimate-website-on-the-left-copycat-on-the-right.png\"\/><\/a><\/figure>\n<p><!\u2013 \/wp:image \u2013><\/p>\n<p><!\u2013 wp:image {\"linkDestination\":\"custom\"} \u2013><\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/web-assets.esetstatic.com\/wls\/2022\/04\/Figure-2b.-PetsMore-legitimate-website-on-the-left-copycat-on-the-right.png\" target=\"_blank\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2022\/04\/Figure-2b.-PetsMore-legitimate-website-on-the-left-copycat-on-the-right.png\" alt=\"Figure-2b.-PetsMore-legitimate-website-on-the-left-copycat-on-the-right.png\"\/><\/a><\/figure>\n<p><!\u2013 \/wp:image \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><em>Legitimate website on the left, copycat on the right<\/em><em>&nbsp;(Source:&nbsp;<\/em><a href=\"https:\/\/www.welivesecurity.com\/2022\/04\/06\/fake-eshops-prowl-banking-credentials-android-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>ESET Research<\/em><\/a><em>)<\/em><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:image {\"linkDestination\":\"custom\"} \u2013><\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/fake-telegram-website.png\" target=\"_blank\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/fake-telegram-website.png\" alt=\"fake-telegram-website.png\"\/><\/a><\/figure>\n<p><!\u2013 \/wp:image \u2013><\/p>\n<p><!\u2013 wp:image {\"linkDestination\":\"custom\"} \u2013><\/p>\n<figure class=\"wp-block-image\"><a href=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/fake-whatsapp-website.png\" target=\"_blank\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/fake-whatsapp-website.png\" alt=\"fake-whatsapp-website.png\"\/><\/a><\/figure>\n<p><!\u2013 \/wp:image \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><em>Websites impersonating Telegram and WhatsApp (Source:&nbsp;<\/em><a href=\"https:\/\/www.welivesecurity.com\/2023\/03\/16\/not-so-private-messaging-trojanized-whatsapp-telegram-cryptocurrency-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>ESET Research<\/em><\/a><em>)<\/em><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Doublecheck the \u201cofficial app\u201d claims<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>In one case&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2022\/04\/06\/fake-eshops-prowl-banking-credentials-android-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">documented by ESET research<\/a>&nbsp;last year, cybercriminals distributed apps for online stores and banks that often didn\u2019t even have an app available on Google Play.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>When downloading a mobile app that should be associated with a popular online service, make sure that the service actually offers such an app. If that\u2019s the case, its official website will contains links to the apps in Google Play Store and\/or Apple App Store. The number and variety of&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-use-fake-chatgpt-apps-to-push-windows-android-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious ChatGPT-themed apps<\/a>&nbsp;is a handy example.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Check the app\u2019s name and description<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Legitimate app developers typically go to great pains to avoid coming across as unprofessional. This also applies to things as mundane as app descriptions \u2013 read through them to see if you can spot poor grammar or inconsistent and incomplete details. These often provide a clue that an app isn\u2019t what it\u2019s claimed to be.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Check the developer\u2019s pedigree<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Tread also carefully when dealing with an app from an unknown app developer with no track record in app development. Don\u2019t be fooled by a name that rings a bell, either \u2013 shady app makers may be misusing the name of a legitimate and well-known entity. Doublecheck if the developer has other apps to their name and that the apps are reputable; if in doubt, search for the developer\u2019s name in Google.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><em>READ ALSO:&nbsp;<\/em><a href=\"https:\/\/www.welivesecurity.com\/2019\/10\/24\/tracking-down-developer-android-adware\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Tracking down the developer of Android adware affecting millions of users<\/em><\/a><em><\/em><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Look out for excessive app permissions<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Last but definitely not least, stay away from apps that require excessive user permissions \u2013 that is, the kinds of privileges that they don\u2019t really need to do their job. A&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2017\/04\/19\/turn-light-give-passwords\/\">flashlight app hardly needs admin rights<\/a>&nbsp;and access to core device functionality.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2 class=\"wp-block-heading\">7 ways to tell that you downloaded a risky app<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Here are a few signs that your newly-installed app could be sketchy:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>The app isn\u2019t doing its job<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>As an example, back in 2018 ESET researchers analyzed a set of&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2018\/04\/05\/google-play-ad-slingers\/\" target=\"_blank\" rel=\"noreferrer noopener\">apps that posed as security solutions<\/a>, but all they did was display unwanted ads and offer pseudo-security.&nbsp;They only mimicked basic security functions with very primitive security checkers that relied on a few trivial hardcoded rules. As a result, they often detected legitimate apps as malicious and created a false sense of security in the victims.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>If your new \u201cgame\u201d turns out to be a gambling platform, something isn\u2019t right. Check again what it is that you\u2019ve actually downloaded.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>It behaves strangely<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Does the app exhibit weird behavior, such as starting up, closing, or failing altogether for no apparent reason? This is one of the most obvious signs that you may have&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2022\/01\/31\/how-tell-if-your-phone-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">downloaded a dodgy app<\/a>.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>You incurred unexpected charges &nbsp;<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>If you\u2019ve spotted unwanted charges on your credit card or phone bill, it could be due to an app you downloaded recently.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>As an example, ESET researchers spotted multiple apps&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2018\/12\/03\/scam-ios-apps-promise-fitness-steal-money-instead\/\" target=\"_blank\" rel=\"noreferrer noopener\">that posed as fitness-tracking tools<\/a>&nbsp;and abused Apple\u2019s Touch ID feature to steal money from iOS users.&nbsp;After a user launched one of the apps for the first time, it requested a fingerprint scan to \u201cview their personalized calorie tracker and diet recommendations\u201d. If the user had a credit or debit card directly connected to an Apple account, the malware would go on to steal money from the victims via fraudulent in-app payments.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Watch out for scams that involve downloading a peer-to-peer (P2P) payment service and offer fictitious products and services at fire sale prices. Because payments are often instant and cannot be canceled, you may lose money by paying for something you will never receive.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:image {\"id\":174417} \u2013><\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/dodgy-ios-apps-1.png\" alt=\"\" class=\"wp-image-174417\"\/><\/figure>\n<p><!\u2013 \/wp:image \u2013><\/p>\n<p><!\u2013 wp:image {\"id\":174418,\"linkDestination\":\"custom\"} \u2013><\/p>\n<figure class=\"wp-block-image\"><a  href=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/dodgy-ios-apps-2.png\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/dodgy-ios-apps-2.png\" alt=\"\" class=\"wp-image-174418\"\/><\/a><\/figure>\n<p><!\u2013 \/wp:image \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><a  href=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/dodgy-ios-apps-1.png\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\">&nbsp;<\/a><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p><em>Figure 4. Sketchy iOS apps asking users to scan their fingers for fitness tracking before showing dodgy payments<\/em><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Strange messages and calls<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Another sign of trouble involves malware spamming out messages from your phone to your contacts (<a href=\"https:\/\/www.welivesecurity.com\/2021\/05\/17\/take-action-now-flubot-malware-may-be-on-its-way\/\" target=\"_blank\" rel=\"noreferrer noopener\">like FluBot does<\/a>). In other cases, your call or text message history may contain unknown entries as malware attempts to make unauthorized calls or send messages to premium-rate numbers.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Battery drain<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Does your device battery get drained far faster than usual? It may be due to background activity that consumes the device\u2019s resources and could ultimately indicate that your device has been compromised by malware.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Spikes in data usage<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>If you experience a major and sudden surge in your internet data usage without any change in your browsing or phone usage habits, it could also be because of an app\u2019s activity in the background.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li><strong>Random ad pop-ups and unknown apps<\/strong><\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>A malicious app may go on to install additional apps in the background and without your authorization. The same goes for pesky adware displaying unwanted ads on your device. If you spot any of this, chances are high you need to act fast.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2 class=\"wp-block-heading\">What to do next?<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>After discovering what you suspect is a sketchy app, remove it or, even better, download reputable mobile security software that will scan your device and remove the app for you.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>If you go the \u201cmanual\u201d route instead, reset your phone to factory settings (prior to that, make sure you&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/2020\/03\/31\/have-you-backed-up-your-smartphone-lately\/\" target=\"_blank\" rel=\"noreferrer noopener\">have your data backed up<\/a>). Alternatively, you may sometimes have to boot up your device in Safe Mode and then remove the app. The video by ESET malware researcher&nbsp;<a href=\"https:\/\/www.welivesecurity.com\/author\/lstefanko\/\" target=\"_blank\" rel=\"noreferrer noopener\">Lukas Stefanko<\/a>&nbsp;shows you how:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>https:\/\/youtube.com\/watch?v=dIIDh1AqUKQ%3Fenablejsapi%3D1%26origin%3Dhttps%253A%252F%252Fwww.welivesecurity.com<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Also, do other potential victims a favor and report the app to the relevant app store from which you downloaded the app. You can also try to claim a refund.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Going forward, if you use apps from the Google Play Store, make sure to enable the&nbsp;<a href=\"https:\/\/support.google.com\/googleplay\/answer\/2812853?hl=en\" target=\"_blank\" rel=\"noreferrer noopener\">Google Play Protect scanning<\/a>&nbsp;on your device. You can also check the apps you\u2019ve downloaded from outside of the Google Play Store. To do so, turn on \u201cImprove harmful app detection\u201d, which will send unknown apps to Google automatically.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:image {\"id\":174421,\"linkDestination\":\"custom\"} \u2013><\/p>\n<figure class=\"wp-block-image\"><a  href=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/google-play-store-play-protect-settings.jpg\" data-rel=\"lightbox-gallery-0\" data-rl_title=\"\" data-rl_caption=\"\" data-magnific_type=\"gallery\" title=\"\"><img decoding=\"async\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/2023\/06\/google-play-store-play-protect-settings.jpg\" alt=\"\" class=\"wp-image-174421\"\/><\/a><\/figure>\n<p><!\u2013 \/wp:image \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>What if you\u2019re an iOS user? Contrary to what many people may think, downloading a dodgy app on iOS, even from Apple App Store, isn\u2019t unheard of. For more on what to do if a bad app(le) slipped through the iOS safety net, head over to our recent deep dive into the topic:<br \/><a href=\"https:\/\/www.welivesecurity.com\/2022\/09\/19\/can-iphone-be-hacked-what-know-ios-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Can your iPhone be hacked? What to know about iOS security<\/a>&nbsp;<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2 class=\"wp-block-heading\">7 tips for staying safe<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Finally, a few quick tips for staying safe while using your mobile device:<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:list \u2013><\/p>\n<ul><!\u2013 wp:list-item \u2013><\/p>\n<li>Stick to Google Play and Apple App Store; i.e., avoid putting yourself at risk by installing apps from third-party stores.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>Don\u2019t mindlessly click on links sent via social media messages or emails.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>Use two-factor authentication (2FA) on all your online accounts that offer it, especially on those that contain your valuable data.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>Keep your phone\u2019s operating system and apps up-to-date.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>Stick to apps whose developers continue to improve their products and fix security vulnerabilities and performance bugs.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li><a href=\"https:\/\/www.welivesecurity.com\/2020\/06\/05\/how-secure-is-your-phone-lock-screen\/\" target=\"_blank\" rel=\"noreferrer noopener\">Secure your device\u2019s screen<\/a>&nbsp;with a passcode sufficient length and complexity or a solid biometric feature such as a fingerprint \u2013 or, ideally, a combination of both!<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/p>\n<p><!\u2013 wp:list-item \u2013><\/p>\n<li>Use mobile security software.<\/li>\n<p><!\u2013 \/wp:list-item \u2013><\/ul>\n<p><!\u2013 \/wp:list \u2013><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You\u2019ve just downloaded a new mobile game, cryptocurrency wallet, or fitness app, but something isn\u2019t right. Your phone\u2019s screen is swamped by annoying ads, the app is not doing what you would expect it do, and, God forbid, you found an unauthorized transaction on your bank account. Chances are good that the app you downloaded [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":6749,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2904,2899,2907],"tags":[],"class_list":["post-6753","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-dom-i-semya","category-kiberprestupnost","category-ustrojstva-platformy"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/posts\/6753","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/comments?post=6753"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/posts\/6753\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/media\/6749"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/media?parent=6753"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/categories?post=6753"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/ru\/wp-json\/wp\/v2\/tags?post=6753"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}