Android Threats Evade Play Store Scrutiny Through Sideloading and Malicious Updates
Android malware increasingly bypasses Google's Play Store protections by exploiting sideloaded applications and malicious updates to legitimate apps.

While downloading applications from Google's Play Store generally offers a layer of security, a significant portion of Android threats originate from outside this curated ecosystem. These malicious applications often reach users through "sideloading" – installing apps from sources other than the official store – or via malicious updates to seemingly legitimate applications that have already been installed.
A prime example of this threat vector is the Albiriox banking Trojan. This Android Remote Access Trojan (RAT) is designed for on-device fraud, performing fraudulent transactions directly on a victim's phone rather than merely stealing credentials. Researchers discovered Albiriox spreading through apps with generic names such as "utility," "security," "retailer," or "investment." Users often did not recall installing these apps from the Play Store, indicating they were sideloaded, distributed via text message links, or downloaded from untrusted websites.
Malwarebytes for Android is specifically designed to counter these threats by scanning devices directly, irrespective of an app's origin. This approach ensures that potentially unwanted programs (PUPs) and other malicious files are detected whether they were sideloaded, bundled with other software, or downloaded through a web browser.
Furthermore, the threat landscape includes legitimate applications that become malicious after installation. In one notable instance, a barcode scanner app with millions of Play Store installs received an update containing heavily obfuscated malicious code. This code, signed with the same digital certificate as previous clean versions, evaded initial detection. Once installed, it would automatically open browsers and redirect users to unwanted websites. This pattern of legitimate apps being updated with malicious code highlights the importance of continuous monitoring.
Malwarebytes' Real-Time Protection (RTP) addresses this by not only scanning new installations but also by treating any new or changed files within existing apps as potentially malicious. If an app receives an update, RTP scans it anew, rather than assuming its safety based on prior installation.
Cybercriminals also employ tactics to hide malware within archives like ZIP files. Malwarebytes' scanner decompress these archives to inspect their contents without altering the original files. Nested archives and APK code are extracted to a temporary, sandboxed location for analysis and then deleted upon scan completion, ensuring no malicious components are left on the device.
Deep scanning requires significant processing power, which can impact device performance and battery life. Malwarebytes optimizes this by adjusting its workload based on available processing power and user settings, allowing scans to run in the background without excessive drain, and can even defer scans until the device is charging.
The threat database is continuously updated to reflect the evolving nature of mobile malware, including sophisticated banking Trojans that can detect and evade security testing environments. By employing over ten specialized scanners that analyze code, behavior, structure, and origin, Malwarebytes aims to catch threats that might slip past a single detection method, providing layered defense against the diverse and evolving Android threat landscape.