Apple's 2025 App Store Transparency Report states that the company blocked over $2.2 billion in fraudulent transactions and removed roughly 59,000 apps for bait-and-switch tactics: publishing one thing to gain approval, then swapping in something else once the app goes live. The year before, fraud accounted for 38,315 of Apple's 82,509 total app removals, roughly 46%, making it the second-largest removal category that year. Google's numbers point in the same direction: its 2025 Play & Android Ecosystem Safety Report states that Google blocked 1.75 million policy-violating apps before developers could publish them, and stopped another 872,000 high-risk apps before they reached a single user.
Unfortunately, these are real, measured numbers, and not a hypothetical risk. But they describe platform-wide enforcement and not protection for any one brand. Apple and Google are policing their stores for policy violations across millions of apps. Neither checks whether a fake app uses your name or logo. That gap between the Apple App Store and Google Play, in platform-wide moderation and brand-specific exposure, is where the damage happens.
A few recent cases illustrate how threat actors are exploiting this exposure.
In July 2025, ThreatFabric researchers found a dropper posing as a "PDF Update" file-reader app climb to the top three in the US Google Play "Top Free Tools" chart, with over 50,000 downloads. The app met all validation requirements when Google approved it, remained dormant for about six weeks, and then operated actively for six days, from June 24 to 30, 2025, before Google took it down. By August 2025, Zscaler ThreatLabz found that the same malware family, tracked as Anatsa/TeaBot, had expanded its fake-overlay targeting to 831 banking and cryptocurrency apps, up from 650 in the previous report. Attackers built one of the new additions, a fake "scheduled maintenance" overlay, specifically for Robinhood.
That same Zscaler report provides a widely cited figure: Google Play removed 77 malicious apps that users had already installed more than 19 million times combined. They didn't all belong to one family. Adware accounted for over 66% of those installs, a family called Joker (and its Harly variant) made up about 25%, and the rest included Anatsa/TeaBot and a family called Maskware. Attackers disguised most of these as ordinary utility, personalization, entertainment, or photography apps rather than named-brand clones. Named-brand impersonation is one route into a user's phone. Looking like a harmless utility is another, and right now it's the more common one.
Brand impersonation still shows up on its own, even outside the app stores. In November 2025, Cleafy Labs found a pixel-accurate fake Google Play listing for PENNY, a mainstream discount supermarket chain in Europe. Developers hosted the page outside the app stores and built it to look like a Google Play Store listing, complete with a fake install button that delivered a banking trojan called Albiriox.
Threat actors rented out Albiriox as malware-as-a-service for $650 a month. It targeted more than 400 financial apps worldwide. PENNY didn't need to be a bank to become a target. It needed to be a brand people trust enough to click without a second thought, on a page that borrowed Google Play's own look to earn that trust.
Our first blog introducing the App Store Threat Detection covered a version of this same pattern: a fake Sparrow Wallet listing that remained on the Apple App Store for months despite the real developer's repeated reports, a case in which three people are now suing Apple. As with that case, what's a matter of public record here is that the lawsuit alleges Apple failed to properly vet the app; there's no ruling, dismissal, or settlement yet. It's worth being clear about what App Store Threat Detection actually does: it surfaces the fake App Store and Google Play listing and builds the evidence file behind it. Filing a takedown request with Apple or Google remains an important step your team should take.
A structural reason emerges for why app stores are an easier target than the open web. An operator must build, host, and discover visitors for a phishing site through link clicks. However, an app store listing discovers visitors for you: search, category rankings, and recommendation algorithms do much of the distribution work that a phishing site's operator would otherwise have to do alone. The apps also live on a platform your customers already trust, outside the kind of monitoring built into most brand protection tools. That combination is how many of the cases above stayed active on the app stores for months before anyone noticed.
If your brand is worth impersonating on the open web, it's worth impersonating in an app store too, and the data above says that's already happening at scale. If you're already running Breach Risk Threat Monitoring, App Store Threat Detection uses the same Transforms and Threat Credits you have today, the same setup, same plan, one more place it looks.
Ready to find out if you already have a doppelganger in one of the app stores? While you're at it, you can now scan more than the App Store and Google Play.
Request a demo of Breach Risk or start a free trial to see what's currently listed under your brand's name.