We present the results of the first large-scale study into Android markets that offer modified or modded apps: apps whose features and functionality have been altered by a third-party. We analyse over 146k (thousand) apps obtained from 13 of the most popular modded app markets. Around 90% of apps we collect are altered in some way when compared to the official counterparts on Google Play. Modifications include games cheats, such as infinite coins or lives; mainstream apps with premium features provided for free; and apps with modified advertising identifiers or excluded ads. We find the original app developers lose significant potential revenue due to: the provision of paid for apps for free (around 5% of the apps across all markets); the free availability of premium features that require payment in the official app; and modified advertising identifiers. While some modded apps have all trackers and ads removed (3%), in general, the installation of these apps is significantly more risky for the user than the official version: modded apps are ten times more likely to be marked as malicious and often request additional permissions.
翻译:本研究首次对提供修改版或定制版安卓应用(即由第三方改变其功能特性的应用)的市场进行了大规模调查。我们分析了从13个最流行的修改版应用市场中获取的超过14.6万个应用。与Google Play官方版本相比,约90%的收集应用存在不同程度的改动。修改内容包括:游戏作弊功能(如无限金币或生命值);免费提供官方需付费的高级功能;以及修改广告标识符或移除广告的应用。我们发现原始应用开发者面临重大潜在收入损失,原因包括:付费应用被免费提供(约占所有市场应用的5%);官方需付费的高级功能被免费开放;以及广告标识符被篡改。虽然部分修改版应用移除了所有追踪器和广告(占3%),但总体而言,安装这些应用比官方版本存在显著更高的用户风险:修改版应用被标记为恶意的可能性是官方版本的十倍,且常要求额外权限。