CYBER WELFARE

Protect your Digital Privacy

Cloned and counterfeit apps, and the other ways a fake app ends up on your phone

An app is recognised mainly by two things: its name and its icon. They are also the two easiest things to copy.

That is why cloned and counterfeit apps — apps built to look like those of a well-known service without actually being them — work so well: they do not need to force anything, they only need to be chosen. Haste and trust in a familiar brand do the rest.

This post explains how these imitations work, along with the other tricks that come in through an installation: from near-identical names to fake updates, all the way to genuine apps that change their nature after an update. It is the threat-side companion to the recommendation on checking an app is genuine before you install it.

One useful clarification: this post describes how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.

The starting point

You are in a town you do not know and you need to pay for parking. You open the app store, search for the local council’s parking app and tap the first result: same icon, same colours, an almost identical name with the word “Pay” added on.

The app asks you to register, then for your card details, to “activate your wallet”. The parking does not show as paid, but the charge goes through. The next day, two more purchases you did not make appear on your statement.

The real app did exist, a few results further down. The one you installed had simply imitated it well enough to be chosen in a few seconds, with the parking meter right in front of you.

Why trust in a familiar name increases the risk

All the attacks that follow share one thing: they do not need to get past your phone’s defences, they only need to persuade you to install.

Your phone’s operating system keeps apps well separated from one another, but it cannot know which app you actually meant to get. If you start the installation yourself, and you grant the permissions yourself — the authorisations an app asks for to use your camera, contacts, messages or other features — then, as far as the system is concerned, everything is in order.

That is why anyone building an imitation focuses on what we actually look at — the name, the icon, the star rating — and on the moments when we look least: when we are in a hurry, when a message seems urgent, when it is a service we trust.

1. Clone apps of well-known brands

In plain terms. An app that copies the look of a familiar service — a bank, a courier, a payment app, a social network — to obtain the details you would give the original.

How it works. The clone app reproduces the original’s logo, colours and screens. Sometimes it manages to stay on the official app stores for a while before being spotted and removed; more often it lives on websites that imitate the official ones. Once opened, it asks for what the real app would ask for: sign-in details, card details, verification codes.

Why trust in the brand helps it. A familiar name lowers your guard. Faced with the “usual” icon, most people do not check who published it.

Possible impact. Theft of sign-in and payment details, unauthorised charges, access to linked accounts.

What should make you suspicious. A developer different from the service itself, a recent publication date for a brand that has existed for years, few reviews or reviews that all sound alike, card details requested before you have received any service.

How to protect yourself. Start from the service’s official website and follow its link to the app store, instead of typing the name into a search. Understanding how app stores check apps helps you know what those checks guarantee and what they do not.

2. Near-identical names (typosquatting)

In plain terms. An app, or a developer, with a name that differs from the original by one letter, an extra word or a symbol.

How it works. Typosquatting — literally “squatting on a typing error” — exploits the way we read: the eye recognises the shape of a word, not every single letter. An “rn” in place of an “m”, an “l” in place of an “i”, an “Official”, “Pro” or “Plus” tacked on the end: in a list of results, the differences go unnoticed. The same applies to the developer’s name, the field that tells you who is behind the app.

Why haste helps it. You look for an app when you need it, often standing up and short of time. That is exactly when you read least carefully.

Possible impact. The same as a clone app, often for longer: a name that resembles the original raises nobody’s suspicions.

What should make you suspicious. Words added to the official name, spelling mistakes or unusual letters, a developer with a generic name or one that is similar but not identical.

How to protect yourself. Read the developer’s name letter by letter and compare it with the one shown on the service’s official website. If in doubt, wait: the real app will still be there.

3. Download links sent by text message or chat

In plain terms. A message invites you to install an app from a link, with a believable pretext: a delivery, a refund, a voicemail waiting for you.

How it works. It is a form of smishing, meaning phishing by text message: a message that imitates a trusted sender to push you into doing something. The link leads to a page that looks like a courier’s or a public body’s, offering to download an installation file directly, outside the app store. To go ahead, the phone warns you that you are installing from “unknown sources”: it is a protection, which the page presents as a normal step.

Why bypassing the app store helps it. An app installed from a link does not go through the official store’s checks. The only filter left is your decision in that moment.

Possible impact. Apps that read your text messages, including verification codes; that display fake screens on top of your banking apps; that send the same message on to your contacts.

What should make you suspicious. An installation link received by message, whoever the sender; a request to allow installation from unknown sources; urgency (“your delivery will be cancelled”); a parcel you were not expecting.

How to protect yourself. A reliable service does not ask you to install an app from a link in a text message. If the message seems plausible, open the app store or the official website yourself and look there. Keep installation from unknown sources switched off.

4. Fake updates

In plain terms. A notice tells you that your phone, your browser or an app needs updating, but the “update” is malicious software.

How it works. The notice usually appears on a web page, sometimes imitating the style of system notifications: “your device is at risk”, “out-of-date version, install now”. The button downloads an app or a file that has nothing to do with the operating system.

Why the habit of updating helps it. Updating is the right thing to do, and we know it. Whoever builds a fake update exploits precisely this good habit.

Possible impact. Installation of spyware, meaning software that secretly collects your data and activity, or of adware, software that floods your phone with advertising.

What should make you suspicious. Updates offered by a web page rather than by your settings; alarmed tones and countdowns; a request to download a file.

How to protect yourself. Real updates come from the system settings or the app store, not from a web page. Keeping your software up to date with automatic updates leaves little room for this trick: if your phone updates itself, an outside notice has no reason to exist.

5. Legitimate apps compromised through an update

In plain terms. A genuine app, installed long ago from the official app store, receives an update that changes how it behaves.

How it works. It can happen in different ways. The developer’s account is broken into, and someone else publishes the update. The app is sold to a new owner with different aims. Or a third-party component used by the app — a library, meaning a ready-made block of code that many developers include in their products — contains a malicious part. This is known as a supply chain attack: one link upstream is hit in order to reach many people.

Why trust already given helps it. The app already has the permissions you granted months ago, and updates arrive automatically. The change can go unnoticed for a long time.

Possible impact. Data collected through permissions already granted, intrusive advertising, subscriptions activated behind your back, unusual battery or mobile data use.

What should make you suspicious. New permissions requested after an update, a change in the developer’s name, advertising that was not there before, recent reviews reporting sudden problems.

How to protect yourself. Here the initial check is not enough, because the app was genuine. Two habits help: checking what your apps can do whenever their permissions change, and removing apps you no longer use, because every installed app is one more door. Updates remain valuable: they fix far more problems than they create.

6. Fake security apps

In plain terms. Apps that promise to protect, speed up or “clean” your phone, and do the opposite.

How it works. They present themselves as antivirus apps, battery optimisers, memory cleaners or VPNs, meaning services that route your connection through an intermediate server. They often arrive after an alarming warning shown on a web page, along the lines of “viruses have been found on your phone”. Once installed, they ask for very broad permissions, such as accessibility services — features designed for people with disabilities, which allow an app to read the screen and act on the user’s behalf — or the device administrator role, which makes the app harder to remove.

Why worry helps it. Someone who fears they have a problem will grant a lot to whoever promises to solve it.

Possible impact. Extensive control of the phone, reading of whatever appears on screen, expensive subscriptions, data passed on to third parties.

What should make you suspicious. Virus warnings that appear on a web page, scans that always “find” something, requests for accessibility services or the administrator role without a clear reason.

How to protect yourself. The operating system already includes built-in protection that checks apps. The resource on fake security apps explains how to recognise the imitations.

7. Apps that change after installation

In plain terms. A simple app — a torch, a document reader, a game — works as promised at first, and only later downloads the harmful part.

How it works. This type of app, sometimes called a dropper (because it “drops” the harmful part later), can get past app store checks because, at the time of review, it contains nothing harmful. After a few days, or after a certain number of uses, it asks to download an “add-on” or a “content pack”. It is often propped up by inflated reviews.

Why star ratings help it. When choosing between similar apps, people often look at the rating and the number of downloads: the two figures that are easiest to inflate.

Possible impact. The same as clone apps and fake updates, with a delay that makes it hard to link the problem to the app that caused it.

What should make you suspicious. A simple app asking for permissions its function does not need; requests to download content from outside the app store; enthusiastic, short reviews clustered in the same period.

How to protect yourself. Ask yourself whether the feature already exists on your phone (a torch and a document reader usually do); read the recent and the negative reviews, not just the average. The resource on fake app reviews explains why the rating tells you little.

Summary table

AttackMain riskWhat should make you suspiciousEffective defences
Clone apps of well-known brandsDetails handed to an imitationDifferent developer, recent publicationStart from the official website, check the developer
TyposquattingA near-identical name mistaken for the originalAdded words, unusual letters, generic developerRead the name and developer letter by letter
Links by text message or chatInstallation outside the app storeInstallation link in the message, urgency, unknown sourcesNo apps from links, unknown sources switched off
Fake updatesMalicious software disguised as an updateNotice on a web page, alarmed tones, file to downloadUpdates only from settings, automatic updates
Apps compromised through an updateA genuine app that changes behaviourNew permissions, sudden advertising, recent negative reviewsReviewing permissions, removing unused apps
Fake security appsExtensive control granted out of fearAlarming scans, requests for accessibility or administrator roleBuilt-in system protection, proportionate permissions
Apps that change after installationHarmful part downloaded laterDisproportionate permissions, inflated reviewsRecent and negative reviews

What they have in common

Seven different tricks, three habits that cut across almost all of them:

  1. Start from the source — the service’s official website or your phone’s settings, not a search result, a message or a web page.
  2. Check who is behind it — the developer’s name, compared with the service’s, matters more than the icon and the stars.
  3. Grant permissions in proportion — an app asking for more than it needs is telling you something, even if it came from the app store.

None of them requires technical skills: only slowing down for the few seconds in which you decide what to install.

Protection checklist

  • ☐ Apps for important services (banking, payments, email, deliveries) installed by following the link on the official website
  • ☐ Developer’s name checked before every installation
  • ☐ No apps installed from links received by text message, email or chat
  • ☐ Installation from unknown sources switched off
  • ☐ Automatic updates on, and no update ever accepted from a web page
  • ☐ Permissions reviewed after every update that asks for new ones
  • ☐ No app has accessibility services or the administrator role without a clear reason
  • ☐ Apps you no longer use removed periodically

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that a fake app does not force its way into your phone: it gets itself chosen by imitating what we trust
SkillsReading an app’s store page — developer, date, permissions, reviews — as a set of clues
Secure BehaviourInstalling only from a verified source, especially when you are in a hurry

Reference level: FL3 — Autonomous, with elements of FL2 — Beginner in the sections on clone apps and links received by text message.

Conclusion

The tricks described here are not aimed at you in particular. They rely on something we all do, often in a rush: tapping “Install” on the app that looks like the right one.

That is why the most effective defence is a habit, not a tool: always start from a verified source, and look at who is behind an app before you look at its icon. To know what to look for before and after installing, the signs of a fake app are the natural next step; if a suspicious app is already on your phone, you will find the steps in what to do after installing a fake app. For a wider picture, you can start from the digital resilience self-assessment.

Something to think about. If you had to reinstall your bank’s app on a new phone today, would you know where to start to be sure it is the real one?

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.