Bbabo NET

Science & Technology News

The number of attacks on the infrastructure of Russian mobile applications increased by 200% in six months

The number of attacks on the infrastructure of mobile applications in Russia has tripled over the past six months, Kommersant reports, citing cybersecurity companies. Experts say that the problem is that half of the developments are based on interfaces with the web version, while the mobile version is not properly checked.

In Informzaschita they say that in the first half of the number of attacks on the Application Programming Interface in Russia increased by 200% compared to 2021. At the same time, in the second quarter, the number of attacks on mobile applications increased four to five times compared to the first. Malicious interventions include data theft, service suspensions, fake accounts, and credit card fraud in banking applications. According to analysts, hacking leads to a denial of service half the time, and account theft occurs 10% of the time.

First of all, the number of attacks has increased due to the removal of a number of Russian applications from Western marketplaces - the App Store and Google Play, says Shamil Chich, an expert at the Informzaschita IZ:SOC Center for Monitoring and Counteracting Computer Attacks. According to him, it became possible to download applications of companies and banks that fell under Western sanctions only in the form of an APK file from the site, but a file made in haste can be infected with a virus.

Another problem with API security is that most companies build web versions and applications on a single interface. This makes development, testing, and support cheaper, but in this case, developers neglect security. Most companies and banks use a scheme with a single backend, says Dmitry Morev, director of cybersecurity at the red_mad_robot developer company - according to him, up to half of the market is now represented by such solutions.

Marketplaces began blocking applications from Russian companies back in the spring. So, the products of VTB, the ecosystems of Sberbank and other organizations that were sanctioned were subject to restrictions. Then the copies of applications disguised as official ones created by attackers became the main risk, Kommersant wrote.

The number of attacks on the infrastructure of Russian mobile applications increased by 200% in six months