How a sideloaded app takes over your phone

You will be able to explain how an APK file from a link can lead to money leaving your bank account.

You're scrolling Facebook and see an ad for a bakery: a box of six durian puffs for S$8, half the usual price. You message the page to order. The friendly seller says orders go through their own app, which gives you the discount, and sends you a link. You tap it, your phone warns you about installing apps from this source, you allow it, and the app asks for a few permissions. You place your order and forget about it.

Two days later, you wake up to find most of your savings gone. Nobody called you. You never typed a password into a strange website. You didn't give anyone a code. The money left while you slept.

This lesson explains how that happens, one step at a time, so that the first step never happens to you.

What an APK is

An APK is an Android app file, the package your phone uses to install an app. When you download an app from the Google Play Store, your phone is quietly installing an APK in the background. The store checks apps before listing them and scans them for known malware. It isn't perfect, but it's a real filter.

You can also install an APK directly, from a link, a website or a file someone sends you. This is called sideloading, and it skips the store's checks completely. Whoever made the file decides what it does. There's no review, no scanning and no way to take it down quickly if it turns out to be harmful.

Android phones block sideloading by default. To install an APK from a link, you have to give the browser or messaging app permission to install unknown apps. Your phone shows a warning when you do this. In the scam above, the victim tapped through that warning because the seller seemed friendly and the deal seemed small.

iPhones work differently, and lesson 6.3, iPhones, remote access apps and screen sharing, covers how scammers go after iPhone users instead.

How the link reaches you

The bait is usually something cheap, local and everyday. Discounted food, a cheap cleaning or aircon servicing package, concert tickets, a deal on seafood, a membership offer. The ads run on social media and in online marketplaces, and the pages often copy the photos and names of real businesses.

When you get in touch, the conversation moves to WhatsApp or another chat app, and at some point you're told you need the shop's own app to order, pay or claim the deal. You get a link to an APK file. Sometimes the app is described as a way to pay a small deposit, which adds a reason to type in your card or banking details.

The deal is deliberately small. A S$8 box of pastries doesn't trigger the caution you'd feel about a large investment, and that's the point. The scammer isn't after the S$8. They're after access to your phone.

What the malware does once it's in

When the app installs, it asks for permissions. Some look harmless, and some are dangerous, and lesson 6.2, The permissions that should make you stop, goes through them one by one. Once the app has the right ones, it can do three things.

It can read your messages. That includes the one-time passwords your bank sends by SMS, so the scammer sees every code the moment it arrives.

It can capture what you type. When you log in to your banking app, the malware records your username and password, or shows you a fake login screen that looks like the real one and keeps whatever you enter.

It can control your screen. The malware can open apps, tap buttons and type, just as you would. Some versions can show a black or fake screen on top so you don't see what's happening underneath.

Put those together and the scammer has everything needed to use your banking app as you.

How the money leaves

Scammers don't usually act straight away. They wait until the phone is idle, often late at night, when you're asleep and won't see the screen light up or notice alerts arriving.

Then they work through your banking app remotely. They log in using the details they captured. When the bank sends a one-time password, the malware reads it. They may add a new payee, raise your transfer limit and send money out in several transfers, sometimes deleting or hiding the notifications as they go. By morning, the money has often moved on through other accounts.

Here is an illustration. Siti, 41, installs a cleaning company's app from a link to book a S$50 home cleaning slot. The booking never happens, and she assumes the business is just disorganised. Four nights later, at 3am, her phone opens her banking app, adds a payee and makes several transfers. She sees nothing until she checks her balance at lunchtime.

This is why the defences in module 7, such as lower transfer limits, alerts and locking part of your savings, matter so much. Lesson 7.2, Money Lock: savings that cannot be moved online, explains how locking part of your savings keeps it out of reach even if someone gets into your banking app.

The one setting that blocks the first step

Everything in this lesson starts with a single action: allowing an app from outside the Play Store onto your phone. If that permission is off, the APK can't install, and the rest of the attack never begins.

On most Android phones, the setting sits under the security or apps section, often called install unknown apps or unknown sources. On newer phones it's set per app, so your browser, WhatsApp and file manager each have their own switch. The exact menu name varies by phone brand.

Most people never need this permission at all. Next, you'll find out whether it's turned on for any app on your phone.

Check whether your phone allows installing apps from unknown sources, and turn the setting off if it is on.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).