A developer's Android app is listed on Google Play with a 4.8-star rating and 5 million installs. They receive an email from 'Google Play Developer Support' saying their app has policy violations and they must click a link to review them. The link goes to play-google-developer-console.com.
What social engineering attack is this, and what is the security risk to the developer and their users if they fall for it?
- A.A. This is a standard Google Play policy alert; clicking the link is safe because Google uses third-party domains for developer communications
- B.C. This is an automated Google Play security scan notification; the link is safe to click but the developer should review their app
- C.B. This is a phishing attack targeting developer account credentials (developer account hijacking); if the developer enters Play Console credentials on the fake domain, the attacker gains full control to push malicious updates to all 5 million users, change bank account details for developer earnings, and access all app analytics and user data