Select your language

Cyberattacks on mobile app users who don't read legal agreements increase

Aumentan ciberataques a usuarios de apps móviles que no leen acuerdos legales

Latin America. According to Business of Apps, 54% of the population in Latin America uses more apps than before the COVID-19 pandemic and users are spending 18 times more time on apps than on websites.

The study indicates that LATAM's growth rate was 27.9, only two points below the global average of 29.9. That's why in recent years, attacks on applications and APIs have become more targeted and automated.

In its recent study, Digital Fortresses Under Siege: Threats to Modern Application Architectures, Akamai warns about legal user agreements for mobile applications that include Terms and Conditions whose information could be used by cybercriminals to breach users' devices. The terms and conditions set out how a product, service or content can be used, in a legally binding manner.

Undoubtedly, accepting a Legal Agreement without reading the fine print can result in a serious security problem if we consider that Latin America has one of the fastest growing application markets worldwide, with a young population that prefers mobile phones and a huge presence of smartphones in all social segments. By 2025, GSMA estimates that there will be 487 million unique mobile subscribers and 812 million SIM connections in Latin America. And he anticipates that by that date smartphones will account for 83% of total connections.

- Publicidad -

Jairo Parra, cybersecurity expert for Akamai Latin America, explained that some legal agreements for applications include the recognition that users accept that their device can be part of a mobile proxy network, in exchange for the services provided by the application. Mobile proxies are IP addresses assigned to mobile devices and are often used to access specific smartphone or tablet services or applications. Cybercriminals can use them, for example, to spread additional malicious payloads, intercept passwords via SMS, or even compromise app sessions such as WhatsApp.

Some applications have also turned mobile devices into proxy network nodes automatically, without users noticing. This can happen either because app developers include it as part of the app's original functionality or because of a threat actor that maliciously installs malware. In the event of a malicious conversion, threat actors can proceed to steal bandwidth and sensitive user information.

On the other hand, Jairo Parra reported that there are also data mining companies that are motivating game developers with attractive incentives to include their mobile software development kit (SDK) in their gaming applications. An SDK is a collection of tools that help developers create and update mobile apps. This offers the user a premium or ad-free experience in exchange for listing their device in a proxy network when the app is running. After the user agrees to allow their device to be part of the web data collection, the computer can still be active as a proxy even if the SDK is running in the background of the app.

According to the Akamai expert, many security teams are finding it increasingly difficult to successfully protect modern applications and APIs, which are riddled with thousands of known vulnerabilities, and attackers are discovering new weaknesses that can be exploited every day. Cybercriminals are currently designing sophisticated campaigns that combine botnets, distributed denial-of-service (DDoS) attacks, and attacks on vulnerabilities in web, mobile, and API applications, among other threats.

According to Akamai's aforementioned study, attacks against applications and APIs increased by 49% between the first quarter of 2023 and the same period in 2024. The exponential growth in demand for applications and APIs has transformed them into lucrative targets for threat actors looking to exploit security gaps to gain unauthorized access to the target's valuable data. Akamai recorded more than 26 billion attacks on applications and APIs in June 2024.

Finally, Jairo Parra stressed that applications and APIs are increasingly important for business success, therefore, before accepting any application, users are advised to stop and read the fine print of legal agreements to understand the risks associated with the use of applications. Similarly, check the ratings and reviews section for any mention of unexpected network behavior or proxy usage.


No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The growing convergence between physical and digital threats is forcing organizations to rethink their security strategies. Faced with this scenario, there is a need for comprehensive approaches...

AI applied to medical security

AI applied to medical security

The Directorate of the Medical Emergency System (SEM), attached to the Ministry of Health of El Salvador, strengthened its technological infrastructure with the modernization of its video...

Eight Red Dot Awards Highlight Innovation in Technology Design

Eight Red Dot Awards Highlight Innovation in Technology Design

International. The technology company Ajax Systems announced that it has won eight awards in the Red Dot Design Award, one of the most prestigious global awards in the field of industrial design....

Villa María del Triunfo reinforces its security with intelligent video surveillance

Villa María del Triunfo reinforces its security with intelligent video surveillance

Peru. The district of Villa María del Triunfo has launched an intelligent video surveillance system that already shows results in terms of citizen security and that will be expanded in a second...

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Denmark. The company reported net income of $340 million in 2025, representing a 10% growth from the previous year. The company spent about a third of this revenue on innovation, with an emphasis on...

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

United States. In response to the growth in demand for monitoring and management software solutions in the security industry, Micro Key Solutions announced the expansion of its operations in Latin...

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Mexico. Grupo Multisistemas de Seguridad Industrial (GMSI) advances in its national growth strategy with the inauguration of new offices in Morelia, Michoacán, with the aim of expanding its coverage...

Case study: Security system modernization with artificial intelligence and centralized monitoring

Case study: Security system modernization with artificial intelligence and centralized monitoring

Mexico City. The Superior Audit Office of the Federation (ASF) implemented an ambitious technological renovation project in its five headquarters located in Mexico City, with the aim of...

Automated key and equipment management strengthens security in mining operations

Automated key and equipment management strengthens security in mining operations

International. Access and equipment management in the mining industry is evolving towards increasingly automated models, in response to operational complexity and occupational safety demands.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter