App Store and Google Play are not perfect filters. By various estimates, hundreds of apps imitating banks, crypto wallets, and payment services pass through them each year. Some are caught within days, others remain for months. How does this happen and what to do about it.
Typical Schemes
Name and icon spoofing. The app is called MetaMask, has a similar logo, but the developer is not Consensys but some SoftLab Solutions. An unsuspecting user downloads a phishing clone with the same interface that steals the seed phrase when connecting a wallet.
Regional imitations. Major banks from different countries are often targeted: attackers publish Sberbank, Sber Online, Tinkoff Black, and similar for European banks. Localized apps find users in the target country.
Crypto wallets with improved UI. Trust Wallet, Phantom, Exodus — all have clones under names like Trust Wallet Pro, Phantom Premium, promising better features.
How to Verify an App is Genuine
Publisher name. Every app listing has a Developer or Seller field. Compare it with what is stated on the official website of the service. If the Trust Wallet website says Six Days, LLC but the store shows BlockChain Tech Inc, do not download.
Publication date and update history. A real bank maintains its app for years with regular updates. A clone usually appeared a month or two ago with few updates.
Reviews. A genuine popular app has tens of thousands of reviews with varied sentiment. A clone has hundreds of reviews, some of which look clearly paid (identical phrasing, high rating, and a suggestion to download right now).
Link from the official website. The safest way is to go from the bank/wallet website to the store, not search the store on your own. The Trust Wallet website has App Store and Google Play buttons that lead to the correct app.
What to Pay Special Attention To
Request for Accessibility permissions. A real banking app almost never requires permission to read everything on screen or simulate gestures. If a banking app asks for it, 95% of the time it is a trojan that uses accessibility to read entered passwords and confirm transfers in the background.
Notifications to disable Google Play Protect. Any request to turn off protection to install our version is 100% malicious.
APK from non-Google-Play sources. On Android, you can install an app from an APK file. Do this only from the official bank website (if they distribute that way), but not from mirrors, mods, or cracked versions.
If You Have Already Installed a Suspicious App
Delete the app immediately. Run an antivirus scan (Malwarebytes, Bitdefender on Android). Change passwords for services you accessed through the suspicious app. If you entered card details, block the card.
A virtual card in 2 minutes
Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.