Behind a seemingly legitimate cover and with the user's consent, many apps track their location and browsing habits when they browse the internet, with the aim of delivering unwanted advertisements to the device or gaining access to social media accounts
One of the most problematic areas regarding the security of mobile communication devices is grayware. The dividing line between legitimate and malicious software is not clear, and so-called grayware often oscillates between the two.
Grayware refers to applications that may not contain any identifiable malware, but can in some way cause harm or annoy the user. For example, they may track the user's location, web browsing habits, and deliver unwanted advertisements. In many cases, grayware creators often maintain a veneer of legitimacy, emphasizing the application's capabilities in the fine print of the software license agreement.
According to data collected by Symantec, more than a third of mobile apps can be considered grayware. Recently, the information security company discovered a grayware app that encouraged Instagram users to share their passwords, aiming to increase likes and followers.
The app, known as InstLike, was available for a while on the Apple App Store and Google Play. The app claimed to provide followers and likes for free. However, it required Instagram login credentials. The app then granted significant control over the user’s Instagram account, automatically liking photos without the user’s interaction.
A type of mobile grayware that has been growing in recent years is known as madware. This refers to applications that aggressively use ad libraries. An ad library is a component of the application that can collect information about the user for the purpose of presenting targeted advertising. It is a common feature of free applications, which usually rely on advertising for their revenue.
However, some ad libraries adopt aggressive tactics, such as leaking personal information, displaying ads in the notification bar, creating images with ads, or changing bookmarks.
A recent study by Symantec revealed that, of the 65 known ad libraries, over 50% are classified as madware. At the same time, the percentage of applications using madware is increasing at a steady rate. For example, 23% of applications on Google Play can be considered madware, while in 2010 it was only 5%.
What can be done about grayware? Due to the fact that it does not cross the boundaries of illegality, companies that have antivirus solutions usually cannot block it. Sometimes, they are removed from official mobile marketplaces such as the Apple App Store or Google Play, as they violate terms and conditions.
Knowledge, experts say, is the best defense. In the same way that PC users are more careful about what they install on their computers, smartphone users need to be aware of what they download to their device and look for what permissions the app is asking us to grant.
There are also a number of tools that can help users identify which applications may be requesting special access to the smartphone, by checking the device for aggressive ad libraries and identifying which applications are associated with them.
Source: protothema.gr

