Why you shouldn’t use pirated Android apps

by: J. Angelo RacomaMarch 13, 2013
Android Malware

Time and again, we hear about Android being the worst platform in terms of security, mostly because it’s rife with malware. Apps that steal personal information and call into expensive premium numbers have purportedly proliferated even the official app repositories at one time or another. Malware is mostly widespread in third-party app marketplaces, though. One thing’s for sure: if an app does not come from Google Play or reputable sources like Amazon AppStore, then there is a higher likelihood of it being tampered with or infected.

Here’s one reason why you shouldn’t use pirated Android apps. It’s very easy to inject malicious code into Android app packages, which means any app out on the wild can potentially include malicious code. If you can download a cracked, free .APK of an app of an otherwise download as a paid application from Google Play, chances are it may already have been tampered with.

A post on Android App Development Ireland blog details how easy it is to inject keylogger code into SwiftKey, one of the more popular third-party Android keyboards (alongside Swype and Touchpal, among others). “Android apps are coded in Java and compiled to byte code that is run on the Dalvik VM and this byte code is not that hard to edit and insert back into an APK,” said the author, who has detailed how he was able to insert keylogger code into the Swiftkey APK, which then resulted in a keyboard replacement that sends all keylogs to the predefined server.

The method involves reverse-engineering the application package with apktool. Then the author injected the keylogger code into the source, after which the app was rebuilt and then signed. The author offers readers access to the hacked APK, which they can test. Results of the logged keystrokes are made available on this site (you can also view previously logged keystrokes from other users).

Again, there’s no doubt that the more open nature of Android (relative to other platforms) makes it more susceptible to malware. Side-loading .APKs from untrusted sources adds to the risk. While there’s nothing inherently wrong about being able to side-load apps to your device, this is just a warning to be more careful with the apps you install.

  • Support the developers. The developers deserve cash for their hard work. Well, except for EA.

    • adreno

      so you suggest people to pirate EA games ? :D

      • Have you seen the dark side?

      • APai

        no avoid them and their games, there will roughly be some other equivalents :)

    • adreno

      so you suggest people to pirate EA games ? :D

  • There are risks associated with any type of piracy. Basically, its best to avoid it and support the developers. If developers have done a great job with the app, they deserve to get paid. Those who choose to use pirated software shouldn’t complain when something goes wrong and must pay for the consequences.

  • APai

    my vote goes for the hardworking developers. how hard is it to spare a buck or two ? it works the same way with IOS too – most developers work for both the platforms. so – support the developers, do NOT sideload from illegal sources. buy the apps when on sale, if the sticker price is high for you. most popular apps are on sale every so often

  • avante

    I only take pirated games for “unlimited money mod” hack. :)
    Blame IAP for that.

    I always bought game that didn’t use any form of IAP. I fully support developer that chose to not use IAP.

    For those of you who like to use “modded” app or games, just ensure:

    1. Get the app from well-known forum. Other user can inform you if app is malicious. Don’t just pick from random website, no-go.

    2. Install good firewall. like droidwall. Prevent stealth internet access.

    3. Install good antivirus. Preferably the one with option to block outgoing call/sms to unknown number, like avast.

  • Victor

  • Momo_

    There is a reason developers hardwork and create the apps. So consumers dont use pirated apps. Pirated apps can harm the mobile phone..

    I do softwaring.. i was able to inject malware and get all my gfs messages through one of apk software, And yes ofcourse with her permission to show her risk and be more careful online.

    If anything is too good to be true then surely comes with some risk. I see people enjoying pirated spotify..surely they have no idea what they are giving away.

    Stay safe