logo

Analysing Third-Party App Stores for Modded APKs Through Signature Verification

ID: 9831111e-dc7c-59c7-8805-934a256754dd

STIX ID: report--9831111e-dc7c-59c7-8805-934a256754dd

Feed Name: CloudSEK Blog

Threat Score
60/100

Date Published: 2020-12-24

Date Updated: 2026-04-27

...
...

CloudSEK analyzed over 50 third‑party app stores and ~990 apps, identifying 10 third‑party apps whose signatures or code differed from official APKs and which contained malicious or risky behaviors (adware, Trojans, fleeceware, and potential RATs). The report describes the APK V1 signature verification process, provides examples of affected apps and stores (e.g., PicsArt, Spotify, Gaana, Truecaller, Pinterest, Oceanofapk, Aptoide), documents malware findings such as Ewind Trojan and SandroRat, explains techniques attackers use to modify apps (debug flags, in‑app billing bypass, admin endpoint exposure, enterprise certificate abuse), and highlights user risk from installing unofficial apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.