Close up of a person's hands interacting with an Android smartphone screen.
© valiantsin suprunovich/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

A new report looking into cyberattack vulnerability in mobile apps found that 57% of apps are at risk, with gaming and financial service (finserv) apps among the chief targets, according to Digital.ai’s 2023 Application Security Threat Report released last week.

Additionally, the study, the first annual report of its kind by Digital.ai, creates a point-in-time benchmark of current threats. This allows researchers and security professionals to accurately measure changes in the landscape in the future.

“The results reveal that 57% of all monitored apps are under attack, with gaming (63%) and FinServ (62%) the most likely to be attacked,” Digital.ai stated in its press release.

“The study found no correlation between an app’s popularity and likelihood of being attacked but found Android apps are more likely to be put in unsafe environments (76%) than iOS apps (55%). Android apps are also more likely (28%) to be run with modified code than iOS apps (6%),” it added.

The report relied on data collected from the company’s application security customers collected between February 1 – February 28, 2023. The aim of the report is to help security professionals identify threats and trends to improve their app security.

Strong Financial Incentive to Crack Gaming and Finserv Apps, Report States

According to Digital.ai, cybercriminals’ have a massive financial incentive behind targeting gaming and finserv apps. It states that the gaming industry is worth over $250 billion dollars and there are many ways to profit from this sustained popularity.

Selling pirated games on grey-market app stores like Cydia is one such option. Cybercriminals can also hack into games with the intention of profiting from their microeconomies.

“For example, Fortnite, a game that arguably peaked in popularity in 2018, still hosts more than a quarter of a billion of monthly active users in 2023, and 68% of those users have spent money on ‘extras’ such as emotes, harvesting tools, gliders, and outfits,” the report states.

“And, with users trading so much real money for ‘game-bucks,’ there is a growing incentive to steal the credit card or PII that makes it easier to steal real money — which in turn creates an incentive for criminal organizations to launder money,” it adds.

Finserv or financial services apps present much more direct incentives since users generally exchange funds or enter payment data on these applications. Considering the stakes involved and the massive potential financial losses and disruption, it is always a good idea to use a top-notch antivirus such as Norton 360.

Android Apps More Vulnerable Than iOS Apps

The report also validates a widely-held belief that Android apps are generally more vulnerable than those in the iOS ecosystem. The general understanding has been that the Apple App Store has a higher security threshold than the Google Play Store. Surprisingly, the report states that the chinks in Android apps have more to do with device vulnerabilities than a more relaxed app store.

“The popular notion is that iOS is more secure than Android because Apple is vocal about its commitment to privacy and has a legacy of running a ‘closed’ environment. However, the reality is more complicated,” the report states.

“IOS, like the Android OS, is an open platform, in the sense that 3rd party developers easily access application build tools. But since Apple controls the production of all iPhones, while Google licenses the Android OS to many different device makers, Android OS is more open and thus more accessible to threat actors.”

Interestingly, the study found that an app’s popularity does not necessarily make it a bigger target for cybercriminals. This could be due to the varying reasons for targeting an app. Apart from financial incentives, cyberattacks are increasingly being used as a strategic tool in geopolitical conflicts.

“While the lack of correlation between the popularity of an app and the likelihood of it being attacked might be illogical to a casual
observer, we know from experience that the reasons and motivations for attacking any particular app are varied. As a result, our customers have determined that building security into their apps is the simplest and best way to prevent attacks on their apps,” the report adds.

Leave a comment