惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
L
LangChain Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
J
Java Code Geeks
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 叶小钗
小众软件
小众软件
博客园 - Franky
D
Docker
Google DeepMind News
Google DeepMind News
Microsoft Azure Blog
Microsoft Azure Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
宝玉的分享
宝玉的分享
C
Check Point Blog
B
Blog
V
V2EX
博客园 - 三生石上(FineUI控件)
MyScale Blog
MyScale Blog
The Cloudflare Blog
博客园 - 聂微东
博客园_首页
Engineering at Meta
Engineering at Meta

Business of Apps

Agentic AI is coming for the app growth playbook [online event] As app discovery expands to ChatGPT, AppTweak launches AI Visibility for Apps Apps in Motion is bringing the best app operators to NASDAQ on April 8 Up your AI game at Business of Apps London 2026 The Business of Apps newsletter is evolving Early bird ticket sale for Business of Apps London ends this week Smadex unveils unique CTV Pause Ads via OpenGlass partnership Build your network at Business of Apps London 2026 Why smaller apps should rethink TV and connected TV for UA Influencer marketing gains traction among AI apps AI agents are becoming the new junior marketers Inside the key themes driving app growth at Business of Apps London 2026 Where is App Store Optimization heading in 2026? [webinar series] From social-first brand to subscription-led app, inside Mob’s rise to the UK’s leading recipe app Apps capture larger share of health and fitness market revenue in 2025 Upcoming RealityMine webinar to highlight blind spots in first-party app data From ad network to scalable performance ecosystem, EVADAV announces a newly enhanced corporate structure The biggest apps and brands are in for Business of Apps London 2026 Diversification takes centre stage in app user acquisition Super early bird ticket sale for Business of Apps London ends this week App-to-web monetisation moves into the mainstream Latest speakers confirmed for Business of Apps London 2026 Agentic coding drives number of iOS apps to highest level ever Smadex and Anzu bring performance and clickability to intrinsic in-game advertising Consumer spending on apps surpassed games for the first time in 2025 The Business of Apps London agenda is now live with more than 70 speakers Opening keynote announced for Business of Apps London ChatGPT was the most downloaded app in 2025, supplanting TikTok Want to speak at Business of Apps London? Branch’s “How I Grew This” episodes land on the Business of Apps podcast
81% of mobile apps vulnerable to cyberattacks
Nayden Tafradzhiyski · 2023-03-22 · via Business of Apps

As more people use apps on their mobile devices, cybercriminals continue to develop new methods to exploit app vulnerabilities. In 2022 cyberattacks rose 38% over the previous year and the number of new mobile malware variants was up 54% in 2019. Promon, the application shielding technology, recently tested 357 high-earning Android mobile games to reverse engineer or manipulate apps. Shockingly, 81% (289) of the apps showed zero defence against these attacks and couldn’t detect a compromised device. 

Defenceless apps

In Promon’s four-step examination, one of the tests involved “repackaging,” a technique used by malicious actors to modify the existing source code of mobile applications. With this technique, hackers can insert their own code on top of an app’s source code and perform additional background tasks outside of the app’s intended functions. 

This opens the door for cybercriminals to steal user login credentials via a tactic called credential stuffing. 

- Advertisement -

Is your privacy opt-in rate costing you $525,000 a year?

The gap between a 65% and 90%+ privacy opt-in rate can mean $525,000 in lost revenue annually for a 100K DAU app — and most teams have no idea where they stand.

This guide breaks down the true cost of consent debt, why the average app sits at just 80% opt-in, and the exact tactics top performers use to consistently hit 90%+: prompt timing, banner design, vendor list optimization, and more.

Download the Guide.

Astonishingly, the tests revealed that a whopping 84% of apps lacked the capability to detect if their source code had been injected with harmful code, leaving them vulnerable to a host of cyberattacks. 

Only 15.7% (56) of apps had deployed any form of repackaging detection, making them the exception rather than the rule.

The company also assessed app vulnerabilities related to hooking frameworks which are utilized to monitor, modify, and redirect events in a mobile application. 

Promon’s tests repackaged almost 85% of all the apps tested

Source: Promon

Serious developers and security experts use them to identify vulnerabilities and malicious activities. However, they can also be used for malevolent purposes like stealing sensitive data. 

Only 5-8% of the apps tested could protect against attacks through frameworks. 

Finally, only one app could detect the presence of a rooted device, leaving the vast majority unprotected and susceptible to a host of security breaches.

13% of apps with $100M or more in annual revenue could detect hooking framework Frida, although none could detect LSposed.

Source: Promon

Why developers must address cyberattacks

Gaming-related cybercrime can be catastrophic for developers and publishers. Where games fail to provide a safe and secure experience, consumer trust declines and developers ultimately make fewer sales and see their downloads dwindle.  

“We were surprised at how many mobile games had a gap in cyber protection. From a technical standpoint, these aren’t complex attacks,” says Benjamin Adolphi, head of security research at Promon.

“These are basic tools and techniques leveraged by cybercriminals every day, and protecting against them should be a priority for developers when building these apps. While attracting millions of players, mobile gaming companies should consider bridging the gap between mobile app protection and ensuring that all gamers enjoy the game. Doing that will not only protect the game experience, but ensure that gaming companies defend their brands and grow their revenue.”

Tools like hooking can modify game code and give players an unfair advantage, causing developers to lose revenue as players may opt-out of in-game purchases.

Worse still, hooking frameworks can be utilized to extract sensitive data like proprietary game code, user data, or cryptographic keys, exposing developers to security risks and IP theft. If games are known to be vulnerable, they risk losing their reputation and player trust, causing lasting damage to the developer’s bottom line.

Key takeaways

  • 81% of apps tested showed zero defence against cyberattacks
  • 84% of apps lacked the capability to detect if their source code had been injected with harmful code
  • Only 15.7% of apps had deployed any form of repackaging detection