Skip to main content
Advertisement
Live broadcast

Extra stores: scammers have launched a series of fake Apple stores

Which schemes are the most dangerous today and how to avoid becoming a victim of intruders
0
Photo: IZVESTIA/Polina Violet
Озвучить текст
Select important
On
Off

The growing interest of Russians in alternative ways of installing applications on Apple devices has led to the emergence of a new fraudulent scheme. Attackers are massively creating websites that mimic the App Store, AltStore, and other Apple-related platforms, promising to install remote banking services and other inaccessible software. According to experts, in the first half of the year, the number of such campaigns increased by 32% compared to the same period in 2025. Users are persuaded to log in with an Apple ID or download a special installer, but instead they risk losing their credentials or infecting their device with malware. The information about which schemes pose the greatest danger today is in the Izvestia article.

How Scammers fake the App Store and AltStore

After removing a number of Russian banking applications and other popular software from the App Store, users are increasingly looking for alternative ways to install them. It is this demand that has become one of the main factors in the emergence of a new fraudulent scheme, representatives of the cybersecurity industry told Izvestia.

According to Informzashchita, in the first half of the year, the number of identified incidents related to counterfeiting of the App Store, AltStore and other app stores increased by 32% compared to the same period in 2025.

So, about 46% of the identified fraudulent resources offered to install banking services or cryptocurrency wallets, Pavel Kovalenko, director of the anti-fraud center at Informzashita, told Izvestia. Another 28% disguised themselves as alternative versions of the App Store, AltStore, or resources for returning deleted applications. The rest distributed games, media services, artificial intelligence resources, and programs to circumvent restrictions.

At the same time, the attackers have long been not limited to creating a single phishing site. Now they are building a whole trust infrastructure — copying Apple's design, publishing instructions, creating Telegram channels, reviews, pseudo-news articles and short videos demonstrating an allegedly working way to install applications, the expert recalled.

A similar trend is noted by analysts of the Smart Business Alert service. Over the past year, experts have identified 3,572 registered domains associated with the names of popular stores. After excluding irrelevant matches, 2864 potentially suspicious domains remained in the sample.

One of the most noticeable spikes was recorded after VK apps were removed from the App Store at the end of June 2026. A week later, experts found 87 new suspicious domains compared to 63 a week earlier. Another wave of registrations occurred in mid-July after the removal of VK and Maks resources from Google Play, said Sergey Trukhachev, head of the Smart Business Alert (SBA) service at ESA PRO.

— Scammers are gradually moving from one-time mailings to the creation of full-fledged "ecosystems of false trust" combining clone sites, instructions, advertising and support channels. One of the most illustrative examples is the FriendlyDealer campaign, which included more than 1,500 fake websites that mimicked official app stores," said Anton Bochkarev, CEO of 3side and 4sec information security companies.

At the same time, the nature of the threats themselves is changing. According to the .RU/ Domain Coordination Center.In the first half of the year, 26,572 requests were received under the Domain Patrol project, which is 22.8% more than in 2025.

The number of requests related to the spread of malware increased almost 2.8 times, from 4,558 to 12,611. As a result, its share in the total threat structure reached 47.5%, while the share of classic phishing decreased to 36.8%. At the same time, more than 97% of dangerous domains were blocked, and the average response time was reduced to 6.2 hours — 2.4 times compared to last year.

— Attacks become more complex, remain unnoticeable for longer, and can lead to more serious consequences than classic phishing. Malware is able to provide attackers with access to accounts on social networks and messengers, banking applications, as well as to private corporate information," said a data analyst at the RU/ Domain Coordination Center.Russian Federation Evgeny Pankov.

What are the dangers of alternative app stores for Apple

Experts emphasize that alternative stores themselves are not dangerous. Risks arise when users download fake versions or install applications from unverified sources.

— By itself, the official AltStore does not disable the built-in protection mechanisms of iOS. The main risk is related not so much to the AltStore as to the origin of the installed IPA file," Vladimir Zykov, director of projects at ANO Digital Platforms, told Izvestia.

According to him, there are no open statistics on AltStore usage in Russia. At the same time, there is still a high interest among users in alternative ways of installing applications, primarily remote banking services.

According to Information Protection, about 43% of malicious downloads through such resources are on Android devices. Most often, attackers distribute banking Trojans, remote access programs, and virus software capable of intercepting SMS messages, notifications, and controlling the gadget.

— Unlike iOS, Android allows you to install apps from the Internet and use alternative stores, which makes it easier to create fakes. But it also gives users the opportunity to download Russian applications deleted from the Play Market from trusted sources — RuStore, AppGallery or from developer sites," said Nikolay Anisenya, head of development at PT Maze.

The iPhone accounts for about 34% of such attacks, Pavel Kovalenko explained. Instead of trying to infect the operating system itself, fraudsters are more likely to use phishing Apple IDs, fake payment forms, fake cryptocurrency wallets, and also offer to install configuration or corporate profiles that allow you to change the network settings of the device. Another 23% of attacks are directed at Mac computers. Under the guise of browsers and updates, hackers distribute stealer programs designed to steal passwords, cookies, keychain data, and information about cryptocurrency wallets.

— Today, hackers are actively using the legitimate mechanism of corporate profiles (MDM), convincing users to install them under the guise of certificates for applications. After that, the device may be under the control of fraudsters," said Igor Bederov, Chairman of the Council for Combating Technological Offenses of the Constitutional Court of the National Security Service of Russia, founder of the Internet Search company.

Experts from F6's cyber intelligence department also point out that messengers and social networks remain the main channel for spreading such threats.

— It is important to separate the alternative method of installing the application from the alternative source of the resource itself. If the instruction is not posted on the official website of the bank or the developer, it is extremely dangerous to trust it," said Mikhail Shurygin, Chairman of the ROCIT Commission on Cloud Technologies, hosting and Information security.

According to experts, the safest way to install applications remains the official website of the developer or the web version of the service. If the user is offered to download the program through an unknown Telegram channel, a third-party website, or is asked to enter an Apple ID on an unfamiliar page, it is better to refuse such an installation.

Переведено сервисом «Яндекс Переводчик»

Live broadcast