McAfee Study Reveals Abuse of Mobile App Permissions
Consumers Unknowingly Granting Access to Scammers in Exchange for Free Apps
SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today released the results of its Mobile Security: McAfee Consumer Trends Report – June 2013, which reveals new ways that cybercriminals abuse app permissions to commit fraud and install malware. The report also shows that games are the most common form of malware-infected app.
“Because of that, cybercriminals are increasingly abusing app permissions as an efficient way to deliver mobile malware. Through these agreements mobile consumers are unwittingly putting their personal information into the hands of criminals disguised as ad networks, and opening up endless doors for scammers.”
McAfee Labs found that under the camouflage of “free” apps, criminals are able to get consumers to agree to invasive permissions that allow scammers to deploy malware. The permissions in free apps, funded by adware, leak personal information which ad networks use to serve targeted ads; however, McAfee found that 26 percent of apps are likely more than just adware. SMS scams and rooting exploits were among the most popular types of threats seen across a variety of apps.
“Most consumers don’t understand or even worry about the app permissions they agree to,” said Luis Blando, vice president of mobile product development at McAfee. “Because of that, cybercriminals are increasingly abusing app permissions as an efficient way to deliver mobile malware. Through these agreements mobile consumers are unwittingly putting their personal information into the hands of criminals disguised as ad networks, and opening up endless doors for scammers.”
Premium Rate SMS Scams: A Pricey Problem
The report examines Fake Installer, a piece of SMS malware disguised within a free app that sends up to seven messages. At a typical premium rate of $4 USD per message, that “free” app can cost up to $28 USD as the malware tells a consumer’s device to send messages to or receive messages from a premium rate SMS number.
Bogus App Ratings: Read between the Stars
The report analyzes FakeRun, malware that tricks users in the United States, India, and 64 other countries into giving an app a five-star rating on Google Play. Once an app developer has been rated highly, other apps they publish will be trusted, which creates more opportunities for a criminal to publish and distribute malware-carrying apps.
Malicious Apps by Category: Games Top the List
The report also identifies the most popular apps that carry malware. Of the top 20 downloads of malware-infected apps, games won the popularity contest, followed by personalization and a tie between tools, music, lifestyle (a cover category for adult content) and TV.
This report draws on several data sources. The McAfee Labs Global Threat Intelligence database, which provided stats on prevalence of mobile malware, is built through data collected by McAfee Labs directly, through collaboration with third party researchers, and from data collected anonymously from McAfee product users. McAfee conclusions about app sources are based on the data collected directly by our McAfee crawlers (for the zoo figure) or by scans of downloads performed by users of McAfee Mobile Security.
For a full copy of the Mobile Security: McAfee Consumer Trends Report – June 2013 with additional threats, please visit: http://www.mcafee.com/us/resources/reports/rp-mobile-security-consumer-trends.pdf .
McAfee, a wholly owned subsidiary of Intel Corporation (NASDAQ:INTC), empowers businesses, the public sector, and home users to safely experience the benefits of the Internet. The company delivers proactive and proven security solutions and services for systems, networks, and mobile devices around the world. With its Security Connected strategy, innovative approach to hardware-enhanced security, and unique Global Threat Intelligence network, McAfee is relentlessly focused on keeping its customers safe. http://www.mcafee.com
Note: McAfee and McAfee Global Threat Intelligence are trademarks or registered trademarks of McAfee, Inc. in the United States and other countries. Other names and brands may be claimed as the property of others.