Cybercrime has caused humongous financial losses worldwide. Losses in 2023 amounted to a staggering $ 8 trillion. Cybercriminals are finding newer ways to perpetrate crimes, leveraging technology. Android has unequivocal dominance in platform and device use. Most transactions are now app-based, and cybercriminals are weaponising some of them for profit.
Introduction
The global security landscape is shifting as cybercrime evolves into a pervasive, costly international crisis. Total losses for 2023 were estimated at a staggering 8 trillion dollars. While early digital threats were largely defined by phishing emails and deceptive websites, newer technologies have shifted the frontline to mobile applications. The ecosystem has transitioned from interpersonal attacks designed to compromise device privacy to sophisticated operations that target victims directly for profit.
The Android Bullseye
The Android platform is the primary battleground in this new era of digital warfare. As of early 2024, approximately 3.9 billion Android users worldwide represent 71 per cent of the global market share. In India, the concentration is even more extreme, with Android holding about 96 per cent of the mobile operating system market. This dominance has made the Indian population a favourite target for cybercriminals looking to exploit the app ecosystem through weaponised apps.
From Viruses to Culpritware
Malware has evolved into a highly resilient tool that is often antivirus-proof and can extract data stealthily while evading forensic investigation. Studies indicate that these applications are frequently downloaded from third-party markets, which often perform substantially worse than official stores in protecting users. Standalone malware has become the mainstream method for creating malicious apps, often injecting payloads into third-party libraries that load during runtime. System event-based activation, such as boot-completed signals, remains a primary trick to activate these malicious payloads. About 96 per cent of modern malware uses at least one anti-analysis technique to avoid detection.
A particularly mysterious threat known as culpritware has also emerged. Culpritware developers often use app generators and hybrid application structures to enable rapid deployment while keeping their origins hidden. Unlike traditional threats, more than half of culpritware is propagated through social media rather than formal app markets. These apps often use access codes and invitation processes to convert victims into accomplices. Furthermore, 96 per cent of culpritware utilises covert fourth-party payment services to finalise transactions, making the financial trail extremely difficult for authorities to follow.
The 400 Million Dollar Subscription Trap
Equally insidious is the rise of fleeceware, which uses deceptive subscription models to incur hidden charges. Users may be tricked into subscribing without consent or find it nearly impossible to cancel after a free trial. In 2021 alone, just 204 of these applications reportedly generated 403.5 million dollars in revenue. Fleeceware is elusive because its code often resembles legitimate applications and it does not exhibit traditional malicious behaviours like stealing data. Instead, it uses dark patterns such as sneaking subscription information or interface interference, where payment details are hidden in tiny fonts or inconspicuous colours to give the impression that the app will not automatically charge fees.
A New Era of Sophistication
The rise of decentralised applications, or DApps, presents new challenges for law enforcement. Because these applications lack a centralised server, they offer anonymity that impedes investigators’ ability to connect digital accounts with real-world identities. DApps are frequently associated with various frauds, phishing attacks, and smart contract vulnerabilities. Technological loopholes such as app virtualisation further complicate the security landscape by using a proxy layer to load plug-in apps stealthily. Additionally, accessibility services are increasingly abused, particularly in applications distributed through social media platforms. Cryptojacking has also become a serious factor, with mining software covertly embedded into free versions of premium apps to mine cryptocurrency using the victim’s device.
The Way Forward: India’s Digital Sovereignty
To combat these threats, India needs a comprehensive strategy that uses law, architecture, norms, and markets to minimise exploitation. A multi-pronged approach is necessary to monitor known aspects of the ecosystem while proactively protecting user data and researching emerging threats through frameworks like the Rumsfeld Matrix. This involves monitoring known risks by following standard operating procedures, collaborating with market services on existing research, and conducting wild research into negative day attacks.
One major proposal involves creating a centralised consortium of academia and researchers to conduct targeted research on the app ecosystem. This group would identify malicious apps and maintain a specialised library to be shared with a regulatory body. This regulatory body would then have the authority to block these applications within India and ensure their removal from app markets. Crucially, applications from developers with mysterious provenance would be prohibited from being downloaded.
One of the most significant hurdles in investigating these crimes is the lack of cooperation from global social media platforms. Many of these companies are incorporated abroad and often ignore requests from Indian law enforcement by claiming they are governed by foreign legislation. To address this, it is proposed that any social media platform operating in India must incorporate as an Indian company subject to the country’s jurisdiction and laws. Under this framework, the Chief Executive Officer of the Indian entity must be an Indian passport holder and resident, ensuring personal liability under domestic criminal and civil law.
Further recommendations include the mandatory local installation of servers containing Indian user data or their mirrors. Cloud passwords should be kept in an escrow account to ensure access when legally required. Additionally, a license from the Ministry of Electronics and Information Technology should be mandatory for all operations in India, with strict penalties for non-compliance. Establishing an automated repository of mobile numbers linked to accounts would also help authorities trace misuse more effectively.
To eliminate fake handles used by criminals and anti-national elements, social media account creation should include mandatory credential verification. This would involve a small financial transaction through net banking or a credit card to verify the user’s identity. Finally, the proposed framework includes heavy financial penalties and criminal liability for platform officials who fail to comply with data requests or orders to remove harmful content. These measures are essential for the nation to gain control over its digital borders and protect the public from the evolving exploitation of the app ecosystem.






