A malicious app is a mobile application designed or modified to steal data, credentials, or money, or to enable other harmful activity. It may look legitimate while requesting excessive permissions, collecting sensitive information, or delivering unwanted advertising and malware.
What a malicious app is in practice
A malicious app is not just a buggy or poorly designed app. It is software that intentionally hides harmful behavior, often by looking legitimate while collecting data, redirecting users, or quietly supporting fraud, spying, or malware delivery.
The key point is intent plus effect: the app’s purpose is to abuse trust, not to provide a normal user service. That can include overt theft, but it can also include covert surveillance, credential capture, or using the device as a foothold for other attacks.
Common ways malicious apps behave
Malicious apps usually rely on deception. They may imitate popular brands, ask for permissions that do not fit their function, or bundle unwanted advertising and tracking code that creates a broader privacy and security problem.
Some malicious apps are simple, while others are layered. A basic fake utility may phish for logins, while a more advanced app may collect device identifiers, intercept notifications, or stage additional payloads after installation. Mobile ecosystem abuse is also a useful lens for NIST AI Risk Management Framework when app behavior is part of a broader trust and misuse pattern.
On mobile platforms, the app itself is often only one part of the attack path. A malicious app can become a delivery mechanism for phishing, session theft, account takeover, or persistence, especially when users grant broad permissions without scrutiny. Campaigns such as Cyberhaven Chrome extension breach 2024 and ShinyHunters Salesforce data theft campaign 2025 show how trusted software can be turned into an access path.
Why malicious apps are difficult to spot
They are difficult to identify because they often mimic legitimate apps in naming, design, and permission prompts. Some remain dormant until after installation, then activate only when the user opens sensitive apps, enters credentials, or approves a prompt.
Mobile app stores and third-party download sites also create uneven trust. Even when the app package is technically valid, the business logic may be deceptive, the privacy collection may be excessive, or the app may be a wrapper for theft and ad abuse. In security terms, the problem is less about the app category and more about what the app is allowed to do once trusted.
From a defensive perspective, that makes behavioral review, permission review, and publisher reputation more important than visual polish alone. The most dangerous apps often succeed because they look ordinary enough to avoid immediate suspicion.
Where malicious apps sit in the security landscape
Malicious apps sit at the intersection of endpoint risk, identity abuse, and mobile privacy exposure. They matter because a compromised app can steal data directly from the device, but it can also steal tokens, session data, or approvals that let attackers move into other systems.
That is why defenders treat malicious apps as part of a wider trust problem, not just a mobile malware issue. Good app hygiene, store controls, and user awareness all reduce exposure, but the underlying challenge is that a harmless-looking app can still behave as an attacker-controlled tool once installed.
Risk and Threat Considerations
Malicious apps create risk because users tend to trust the app surface before they understand the app’s behavior. Once installed, the app can harvest data, abuse permissions, or serve as a stealthy collection point for credentials, messages, and other sensitive content.
Failure mechanism: The app gains access through social engineering, misleading branding, or excessive permissions, then converts that access into theft, surveillance, or further compromise.
Impact: The result can be account takeover, data loss, financial fraud, privacy exposure, or a broader compromise path that reaches other devices and services.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1583 — Acquire Infrastructure | Malicious apps often rely on deceptive infrastructure and delivery channels to reach users. |
| Recommendation — Map delivery infrastructure to attacker staging patterns and monitor for malicious app distribution. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Malicious apps often target credentials, tokens, and session material. |
| Recommendation — Protect and rotate credentials that a malicious app could steal or misuse. | ||
| CIS Controls v8 | CIS-2 — Inventory and Control of Software Assets | Malicious apps exploit unauthorized or unreviewed software on user devices. |
| Recommendation — Track installed apps and remove unapproved mobile software from managed devices. | ||
| OWASP ASVS | V13 — Configuration | The term involves excessive permissions and unsafe app configuration behavior. |
| Recommendation — Review app permissions and configuration to prevent overbroad access. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Malicious apps often steal or abuse login material used to access accounts. |
| Recommendation — Harden authentication paths and detect token theft tied to rogue apps. | ||
Practitioner Guidance
Why practitioners should care: Malicious apps are often judged by appearance instead of behavior, which means the real control problem is trust verification, not just malware scanning. Security teams should pay attention to permission mismatches, unusual update behavior, and apps that request access far beyond their stated function.
Common misunderstanding: A polished interface or presence in an app store does not make an app safe. The practical question is whether the app’s requested access and observed behavior are consistent with its legitimate purpose.
Practitioner takeaway: Treat mobile apps as part of the attack surface, and review them with the same skepticism you would apply to any other third-party software that can touch sensitive data or accounts.
Related resources from NHI Mgmt Group
- Who is accountable when a malicious connected app is authorised by an employee?
- Who is accountable when a malicious OAuth app keeps reading mail after a password reset?
- Why do mobile permissions become a governance problem once a malicious app is installed?
- What fails when a malicious npm package reaches a mobile app build pipeline?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org