The most common ways malware gets access to devices are the following:
- Google Play
- Third-party markets and sideloading
- Malicious ads and exploits
In the first two cases, malware authors generally rely on social engineering, tricking users into installing a potentially useful app. There are many techniques used to make this possible, such as the following:
- Similar design: The app may look like and have a similar name to some other well-known, legal application
- Fake reviews: To make the app look authentic and not suspicious
- Anti-detection techniques: To bypass automatic malware scanners and prolongate the hosting
- Malicious update: The original application uploaded to the store is clean, but its update contains hidden malicious functionality
- Luring description: Promises free or forbidden content, easy money, and so on
Another option here is that the app itself will actually be legal, but will also contain hidden, embedded malicious functionality. There are multiple ways...