“I Thought It Was a Free Trial App”
How a Repackaged App Stole Advertising Revenue and Damaged User Trust

“I thought it was a free trial version. But there were so many ads, and the app kept getting slower.”
This story began with feedback from a user of a beauty app.
At first, it seemed like a minor inconvenience. Since it appeared to be a free version, the user assumed that seeing more advertisements was simply part of the experience.
However, over the following days, several unusual issues began to appear:
-
Advertisements appeared even when the app was not open
-
Full-screen ads were forced to display whenever the user changed screens
-
Battery consumption and device overheating increased significantly
Eventually, the user uninstalled the application.
Only afterward did they discover the truth.
The app was not a legitimate free trial version. It was a repackaged counterfeit version of the official beauty app.
Users Were Frustrated, but the Company Suffered Even More
The real victim of the repackaged application was not only the user.
-
Advertising revenue was redirected to attackers
-
Users became dissatisfied and abandoned the official service
-
Brand ratings and reviews deteriorated rapidly
On the surface, it looked like an app with excessive advertising.
In reality, the company’s entire business model was being undermined.
How the Attack Worked
The investigation revealed a common but highly effective attack pattern.
Confirmed Attack Scenario
-
The legitimate beauty app was repackaged
-
Third-party advertising SDKs and malicious code were inserted
-
Attacker-controlled advertisements were displayed during app launches and screen transitions
-
The official advertising monetization model was bypassed and revenue was diverted
Users believed they were using the official application.
Advertisers believed they were paying for legitimate traffic.
Ultimately, the service provider absorbed the damage.
Where Did Security Fail?
The root problem was surprisingly simple.
-
There was no reliable verification that the app was the official version
-
Unauthorized libraries embedded within the app were not detected
In other words:
The assumption that “if the app runs, it must be legitimate” created the opportunity for the attack.
Repackaged apps rarely break core functionality.
As a result, users often continue using them without realizing anything is wrong.
Meanwhile:
-
Advertising revenue is stolen
-
User trust continues to decline
How Was It Stopped?
The primary defense against this threat was LIAPP.
When an application launches, LIAPP verifies:
-
Application signatures
-
Code integrity
-
Library structure
This enables the platform to identify applications whose structure differs from the official release.
What LIAPP Detects
-
Applications containing unauthorized advertising SDKs
-
Repackaged applications with malicious libraries
-
Modified applications attempting to imitate the official version
Tampered applications can be blocked before they are allowed to run.
As a result, the revenue theft channel was eliminated at its source.
What Changed After Deployment?
The improvements appeared quickly after implementation.
-
Unauthorized advertisements disappeared
-
User complaints declined significantly
-
Official app ratings recovered
-
Advertiser confidence returned
Most importantly, the organization realized something critical:
“Protecting advertising revenue was not a marketing problem. It was a security problem.”
Key Lessons
Repackaged applications are far more than simple software piracy.
They:
-
Directly attack revenue streams
-
Drive users away
-
Erode brand trust
For beauty apps and other ad-supported services, protecting application integrity is essential.
Brand Protection Starts with App Integrity
For applications that depend on advertising revenue, defending against repackaging attacks is no longer optional.
It is a business-critical security requirement.
#RepackagedApps #FakeApps #BeautyAppSecurity #MobileSecurity #AdFraud #AppTampering #MaliciousAdvertising #BrandProtection #MobileAppSecurity #CyberSecurity #AppIntegrity #LIAPP