Attackers are using fake authenticator apps on App Store to scam users

Ashwin
Feb 23, 2023
Updated • Feb 23, 2023
Apple
|
5

Last week, Twitter decided to remove SMS 2FA for its free users. That isn't actually a terrible idea, but for the fact it decided to make SMS 2FA a premium feature for Twitter Blue subscribers.

Attackers are using fake authenticator apps on App Store to steal QR codes

What's worse about this is that the social network failed to recommend a proper 2FA app to its users, instead it just told them to use any authenticator app they wanted to. This was a problem in itself, because not everyone is tech-savvy, some users may not even know what 2FA is, let alone which app to use for securing their account. This is where things became dark, 9to5Mac reports that scammers decided to cash in on users trying to find 2FA apps, and started advertising some fake apps on the iOS App Store.

Image courtesy: Mysk

Fake authenticator apps on the App Store are stealing QR codes from users

The scam authenticator apps were spotted by Mysk, a security researcher/developer team of 2.  They pointed out that scammers were likely using a white-label app that they buy, rebrand, and publish on the App Store. These fake authenticator apps are free to download, probably to trick the unaware user to download it on their iPhone.

But there's a catch, these apps have in-app purchases, and once you install one of these apps and run them, they prompt you to buy a subscription for a fee of $40/year, and even offer a free 3-day trial. At least one of the apps do not let the user scan QR codes without paying the fee, then they steal the QR codes and send the data to the developer. You can view a video demo of these fake apps here, notice how they have similar icons and UIs? These scammy practices are explicitly forbidden by the App Store's rules. So, how these apps passed Apple's reviews remains a mystery.

Fake iOS Authenticator apps 2FA are scamming users

Another security researcher shared some insight on this, they said that the scammers were exploiting the App Store's search algorithm by releasing the same app under different accounts with different metadata sets. One of these fake authenticator apps is reportedly ranking at number 5 in the search results for "Authenticator" in the US App Store. That could be because the scammers are running ad campaigns on the App Store to promote their apps. These apps still exist, I was able to find 2 of them while writing this article.

Scam authenticator apps on the iOS App Store are a problem

Scam apps on the App Store aren't exactly a new threat, despite Apple's claim that it is safer than Android's Play Store, there are several fake ChatGPTs on the App Store too. You shouldn't use them. It is common knowledge that SMS two-factor authentication (2FA) is highly insecure, anyone with access to your phone or SIM card (SIM Swap attack), can get your verification code quite easily. You must instead use a proper 2FA app with Time-based One-Time Passwords (TOTP). If you don't know how to set up 2FA for your Twitter account, you should read Martin's article to learn how to protect your social ID.

Surprisingly, Mysk said  that Authy and Microsoft Authenticators phone home with some usage data, apparently the apps sends information about every QR code that is scanned, to add a 2FA token. Google Authenticator on the other hand was recommended as a safer option. I recommend using Aegis for Android and Raivo OTP for iOS, both of which are free, open source apps.

On a sidenote, there is a new malware called Stealc that's stealing user data from PCs.

Summary
Attackers are using fake authenticator apps on App Store to scam users
Article Name
Attackers are using fake authenticator apps on App Store to scam users
Description
Fake authenticator apps on the App Store are being used to scam users. Some of these apps require subscriptions to scan QR codes and send the data to the developers.
Author
Publisher
Ghacks Technology News
Logo
Advertisement

Tutorials & Tips


Previous Post: «
Next Post: «

Comments

  1. Anonymous said on May 25, 2023 at 9:34 am
    Reply

    How do I get rid of it.

    I removed it from my phone but every time I try to open outlook it takes me to the same authenticator.

    I cannot bypass and therefore cannot use outlook at all.

    Can anyone help?

  2. ilev said on February 23, 2023 at 7:33 pm
    Reply

    The fake authenticator apps on App Store have been removed.

  3. John G. said on February 22, 2023 at 2:01 pm
    Reply

    Thanks @Ashwin for this article that shows the terrible lack of security in those “app stores”. Sites like Google Store, MS Store and so forth are full to the brimm of gargabe and dangerous apps. I talked some time ago with a friend whose father worked in a big tech related company and he said that there are so many apps in those stores that it’s impossible to control them. It’s quite obvious that we need some kind of external supervision to stablish reasonable criteria for increase the user’s protection.

    1. Ashwin said on February 22, 2023 at 2:19 pm
      Reply

      We just need the EU to slap a hefty fine on them, and watch how the stores magically clean themselves.

      1. John G. said on February 22, 2023 at 3:40 pm
        Reply

        @Ashwin +100

Leave a Reply

Check the box to consent to your data being stored in line with the guidelines set out in our privacy policy

We love comments and welcome thoughtful and civilized discussion. Rudeness and personal attacks will not be tolerated. Please stay on-topic.
Please note that your comment may not appear immediately after you post it.