RSS Amplifier

Appknox HQ · Jul 8, 2026

Ghost apps: When the breach comes from an app you never built

0
Sign in to vote or save

Rucha · Appknox HQ


Most security teams measure safety by what they can see inside their own walls. The repo. The release pipeline. The listing on the store page they own.

It is a comforting view. It is also a partial one.

Because the apps that do the most damage are the ones a company never wrote, never reviewed, and never knew existed.

A lot of brand-driven fraud does not begin with weak security. It begins when someone publishes in your name. And your customers believe them.

The real problem is not the app you protect.

It is the app you cannot see.

And in early 2026, a wave of fake Coretax apps in Indonesia showed exactly how costly that blind spot can be.

When the fake Coretax apps appeared, nothing looked unusual at first. Lookalike apps are an everyday occurrence in mobile fraud.

But the detail that made this one work was painfully simple. Coretax, Indonesia’s national tax platform, at that time, had no mobile app at all. It lived only on the web. So when an APK promising a Coretax app landed in someone’s WhatsApp during tax season, there was no real version to check it against.

Group-IB tracked the campaign from July 2025 into a sharp spike in January 2026, timed to the national filing rush. Victims were messaged by people posing as tax officers, walked through a phone call, and guided to sideload the file. Once installed, the malware gave attackers full control of the device and a path to move money out. Group-IB put the losses at USD1.5 - 2 million, with the same infrastructure reused to impersonate more than 16 other government and financial brands.

Attackers had worked out three things:

  • The brand was trusted

  • There was nothing official to compare against

  • The same kit could be aimed at other brand

At that point, the fake app was no longer just a scam. It was reusable fraud infrastructure..

Because a counterfeit app turns dangerous the moment a familiar name meets an unguarded channel.

Security teams pour enormous effort into the apps they own.

Attackers do not always need to break them.

They would rather publish their own version and let your reputation do the convincing.

That is the gap.

Many companies still judge their mobile risk by what sits in their own store listing and their own build. That tells you about the app you made. It says far less about the fakes moving through third-party stores, chat apps, and sideload links right now.

A flawless app on your store page is no comfort if your customers are installing a different one.

So the number of fakes keeps climbing while the brand on the receiving end never sees them.

The hard question in mobile app security is moving.

It used to be about the build.

Now it is about the spread.

The question worth asking is not only

“Have we secured our app?”

It is also:

“Who is shipping apps in our name, and where?”

Once you ask it that way, the priorities shift.

Where your brand turns up matters as much as how clean your code is. Who is publishing as you matters can become as urgent as your latest scan result. The channel matters as much as the build.

Because attackers rarely bother breaking your app.

They just need your customers to install theirs.

Mobile security spent years ending at the edge of the app:

Write it. Test it. Harden it. Release it.

But a brand does not end at its own store listing. It exists anywhere someone can put an app online and attach your name to it. The work ahead is not only defending the app you build. It is keeping watch over the apps built in your name.

That is why the Appknox team built Storeknox.

Storeknox is not one more scanner pointed at your own code. It is a set of eyes on the places you do not own. It continuously sweeps official and third-party stores for the counterfeit, cloned, and repackaged apps trading on your brand, and helps teams move from detection to takedown before fake apps turn into customer harm.

Storeknox watches for:

Fake, cloned, and repackaged apps across official and third-party stores

Apps impersonating your brand and your developer accounts

New listings early on, not when a user reports them

Takedowns, so a detection can turn into a removal

So teams can catch the apps cashing in on their name before they scale into customer damage.

Because attackers are not after your code.

They are after the trust attached to your name.

Security teams keep guarding the apps they built. Attackers keep shipping the ones they did not. Increasingly, the gap between the two decides which app a customer opens first.

See who is publishing apps in your name with Storeknox

Storeknox: a system to secure app distribution across stores

A spotless build does not protect you from cloned listings and fraudulent apps sitting in marketplaces that your tools never look at. How to bring the distribution surface under watch.

All clones aren’t equal: spotting harmless AI wrappers vs malicious fakes

Appknox’s research team on how attackers turn a trusted name into the attack itself, and why mimicking credibility now beats building malware from scratch.

Read the original on appknoxhq.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.