Featured Article

Android’s new real-time app scanning aims to combat malicious sideloaded apps

Here’s our hands-on review of the new Android security feature

Comment

a blue background with eyes featuring a red phone in the middle
Image Credits: Bryce Durbin / TechCrunch

Android’s in-built security engine Google Play Protect has a new feature that conducts a real-time analysis of an Android app’s code and blocks it from installing the app if it’s considered potentially harmful.

Google announced in October the new real-time app scanning feature built into Google Play Protect that the company says can help catch malicious or fake sideloaded apps installed from outside the app store. These apps will morph their appearance or use AI to alter the apps’ code in a way that helps them avoid detection.

Google said this Play Protect feature now recommends a real-time app scan for any new app that has never been scanned before. This consists of a code analysis that will “extract important signals from the app and send them to the Play Protect backend infrastructure for a code-level evaluation.”

Android’s app store has billions of apps that Google screens for malware, though not always successfully. Many device owners also take to sideloading Android apps, which skirt the app store altogether and its many lines of defense. Sideloading remains a popular feature for Android users, even if it means having to trust that the app they are installing is not malicious.

One of the key reasons for Google to introduce its enhanced real-time code-level scanning feature is to counter the proliferation of predatory loan apps. These apps have resulted in the harassment of users, leading in some cases to victims taking their own lives. Bad actors gain access to user data, including contacts and photos, which are used to bully users. TechCrunch extensively covered the impact of predatory loan apps on Indian users. Google also said it took down over 3,500 such apps in the year for violating its policy requirements. Attackers still find ways to target their victims.

“Our policies are making it tougher for predatory apps to be listed on the Play Store. But the bad actors are inventive, and they are finding new ways to trick people and that is why we take additional measures,” said Saikat Mitra, Google’s head of trust and safety for APAC at the Google for India event in New Delhi last month, while announcing the update to Play Protect.

Google initially launched the Play Protect update in India, with plans to soon expand internationally. TechCrunch tried the feature out for ourselves by loading a phone with a variety of malicious and bad apps to see what would make it through.

We tried to install more than 30 different malicious apps, from stalkerware and spyware to predatory loan apps and fake ripoffs of popular apps. Google Play Protect blocked nearly all of the malicious apps with warnings like, “Apps from unknown developers can sometimes be unsafe,” and “This app tries to spy on your personal data, such as SMS messages, photos, audio recordings, or call history,” or, “This app is fake.” A handful of recently created predatory loan apps, however, were successfully installed.

three screenshots showing Google Play Protect's real-time app scanning in effect
Screenshots showing Google Play Protect’s real-time app scanning checking to see if an app is malicious. Image Credits: Google

To test out the scope of the Play Protect update, we used a Pixel 7a with a fresh install of Android 14 with the updated Google Play Store featuring real-time code-level scanning.

We began the testing on the Pixel 7a by trying to install various spyware apps that have rebranded or been cloned, or otherwise had code changes that would attempt to evade detection. (We’re not naming or linking to the apps given their malicious nature.) Commercial surveillance apps, like stalkerware or spouseware, are typically surreptitiously installed by someone with physical access to a person’s phone, often a spouse or domestic partner. These spyware apps silently and continually upload the contents of the person’s phone, including messages, photos and real-time location data, and present a major security and privacy risk to the people whose phones are compromised.

Play Protect intervened each time we tried to install spyware and stalkerware. The feature blocked the apps from installing, labeling the apps “harmful.”

We also picked a handful of predatory loan apps that were disguised as popular Android apps. These loan apps upload the device’s contact list to a server under the guise of fraud prevention, and loan agents can use this access to send threatening and intimidating messages and calls to their contacts. The landing page of one of the predatory loan apps resembled a regular Google Play listing, but required the user to download and manually sideload the app from outside the app store.

The Play Protect update did not restrict five predatory loan apps from installing at the time of our testing.

We also tried to install a couple of apps that appear to be fake versions of other popular apps listed on Google Play. The apps we tested are similarly named and feature near-identical designs and user experiences, but are clearly underdeveloped knock-offs. One of the fake apps imitated a popular game and the other masqueraded as a widely used VPN app.

Play Protect allowed these two apps to be installed, though it’s unclear for what purpose the fake apps were initially developed.

“With this recent enhancement, we’re adding real-time scanning at the code-level to Google Play Protect to combat novel malicious apps, regardless of if the app was downloaded from Google Play or elsewhere,” said Google spokesperson Scott Westover in an email to TechCrunch when reached for comment. “These capabilities will continue to evolve and improve over time, as Google Play Protect collects and analyzes new types of threats facing the Android ecosystem.”

Sideloading allows the freedom to install any Android app but not without risk. Faced with an ongoing deluge of apps that quickly change their appearance and code, Google’s new real-time app scanning feature is an important last line of defense for billions of users and bound to only improve over time.

These Android features will help protect your digital privacy

More TechCrunch

Featured Article

Inside Apple’s efforts to build a better recycling robot

Last week, TechCrunch paid a visit to Apple’s Austin, Texas manufacturing facilities. Since 2013, the company has built its Mac Pro desktop about 20 minutes north of downtown. The 400,000 square foot facility sits in a maze of industry parks, a quick trip south from the company’s in-progress corporate campus. In recent years, the capital…

14 mins ago
Inside Apple’s efforts to build a better recycling robot

Early attempts at making dedicated hardware to house artificial intelligence smarts have been criticized as, well, a bit rubbish. But here’s an AI gadget-in-the-making that’s all about rubbish, literally: Finnish…

Binit is bringing AI to trash

Temasek has previously invested in Lenskart, and this new funding follows a $500 million investment by the Abu Dhabi Investment Authority last year.

Temasek, Fidelity buy $200M stake in Lenskart at $5B valuation

Less than one year after its iOS launch, French startup ten ten has gone viral with a walkie talkie app that allows teens to send voice messages to their close…

French startup ten ten reinvents the walkie-talkie

Featured Article

Unicorn-rich VC Wesley Chan owes his success to a Craigslist job washing lab beakers

While all of Wesley Chan’s success has been well-documented over the years, his personal journey…not so much. Chan spoke to TechCrunch about the ways his life impacts how he invests in startups.

16 hours ago
Unicorn-rich VC Wesley Chan owes his success to a Craigslist job washing lab beakers

Presumptive Republican presidential nominee Donald Trump now has an account on the short-form video app that he once tried to ban. Trump’s TikTok account, which launched on Saturday night, features…

Trump takes off on TikTok

With fewer than 400,000 inhabitants, Iceland receives more than its fair share of tourists — and of venture capital.

Iceland’s startup scene is all about making the most of the country’s resources

Kobo put out a handful of new e-readers a few weeks back: color versions of the excellent Libra 2 and Clara, as well as an updated monochrome version of the…

Kobo’s new e-readers are a sidegrade most can skip (with one exception)

In an interview at his home near Reykjavík, the entrepreneur-turned-VC shared thoughts on his ventures and the journey that led him from Unity to climate tech, a homecoming of sorts.

Unity co-founder David Helgason’s next act: Gaming the climate crisis

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. Over the past eight years,…

Fisker collapsed under the weight of its founder’s promises

What is AI? We’ve put together this non-technical guide to give anyone a fighting chance to understand how and why today’s AI works.

WTF is AI?

President Joe Biden has vetoed H.J.Res. 109, a congressional resolution that would have overturned the Securities and Exchange Commission’s current approach to banks and crypto. Specifically, the resolution targeted the…

President Biden vetoes crypto custody bill

Featured Article

Industries may be ready for humanoid robots, but are the robots ready for them?

How large a role humanoids will play in that ecosystem is, perhaps, the biggest question on everyone’s mind at the moment.

2 days ago
Industries may be ready for humanoid robots, but are the robots ready for them?

VCs are clamoring to invest in hot AI companies, and willing to pay exorbitant share prices for coveted spots on their cap tables. Even so, most aren’t able to get…

VCs are selling shares of hot AI companies like Anthropic and xAI to small investors in a wild SPV market

The fashion industry has a huge problem: Despite many returned items being unworn or undamaged, a lot, if not the majority, end up in the trash. An estimated 9.5 billion…

Deal Dive: How (Re)vive grew 10x last year by helping retailers recycle and sell returned items

Tumblr officially shut down “Tips,” an opt-in feature where creators could receive one-time payments from their followers.  As of today, the tipping icon has automatically disappeared from all posts and…

You can no longer use Tumblr’s tipping feature 

Generative AI improvements are increasingly being made through data curation and collection — not architectural — improvements. Big Tech has an advantage.

AI training data has a price tag that only Big Tech can afford

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: Can we (and could we ever) trust OpenAI?

Jasper Health, a cancer care platform startup, laid off a substantial part of its workforce, TechCrunch has learned.

General Catalyst-backed Jasper Health lays off staff

Featured Article

Live Nation confirms Ticketmaster was hacked, says personal information stolen in data breach

Live Nation says its Ticketmaster subsidiary was hacked. A hacker claims to be selling 560 million customer records.

2 days ago
Live Nation confirms Ticketmaster was hacked, says personal information stolen in data breach

Featured Article

Inside EV startup Fisker’s collapse: how the company crumbled under its founders’ whims

An autonomous pod. A solid-state battery-powered sports car. An electric pickup truck. A convertible grand tourer EV with up to 600 miles of range. A “fully connected mobility device” for young urban innovators to be built by Foxconn and priced under $30,000. The next Popemobile. Over the past eight years, famed vehicle designer Henrik Fisker…

2 days ago
Inside EV startup Fisker’s collapse: how the company crumbled under its founders’ whims

Late Friday afternoon, a time window companies usually reserve for unflattering disclosures, AI startup Hugging Face said that its security team earlier this week detected “unauthorized access” to Spaces, Hugging…

Hugging Face says it detected ‘unauthorized access’ to its AI model hosting platform

Featured Article

Hacked, leaked, exposed: Why you should never use stalkerware apps

Using stalkerware is creepy, unethical, potentially illegal, and puts your data and that of your loved ones in danger.

3 days ago
Hacked, leaked, exposed: Why you should never use stalkerware apps

The design brief was simple: each grind and dry cycle had to be completed before breakfast. Here’s how Mill made it happen.

Mill’s redesigned food waste bin really is faster and quieter than before

Google is embarrassed about its AI Overviews, too. After a deluge of dunks and memes over the past week, which cracked on the poor quality and outright misinformation that arose…

Google admits its AI Overviews need work, but we’re all helping it beta test

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. In…

Startups Weekly: Musk raises $6B for AI and the fintech dominoes are falling

The product, which ZeroMark calls a “fire control system,” has two components: a small computer that has sensors, like lidar and electro-optical, and a motorized buttstock.

a16z-backed ZeroMark wants to give soldiers guns that don’t miss against drones

The RAW Dating App aims to shake up the dating scheme by shedding the fake, TikTok-ified, heavily filtered photos and replacing them with a more genuine, unvarnished experience. The app…

Pitch Deck Teardown: RAW Dating App’s $3M angel deck

Yes, we’re calling it “ThreadsDeck” now. At least that’s the tag many are using to describe the new user interface for Instagram’s X competitor, Threads, which resembles the column-based format…

‘ThreadsDeck’ arrived just in time for the Trump verdict

Japanese crypto exchange DMM Bitcoin confirmed on Friday that it had been the victim of a hack resulting in the theft of 4,502.9 bitcoin, or about $305 million.  According to…

Hackers steal $305M from DMM Bitcoin crypto exchange