What is 'app impersonation' and how do threat actors use it to steal credentials from legitimate app users?
- A.Impersonation is blocked automatically by both catalogs, and a submission whose name or icon resembles a published listing is rejected during processing because the pipeline runs a similarity check (the comparison covers the artwork alongside the title): the credential theft the question describes has no route to a user, and the remaining risk sits with sideloaded copies
- B.Impersonation is a branding dispute rather than a security matter, and the remedy is a trademark complaint because no technical control is involved (the store forwards the notice to the publisher): the credential question does not arise, and the two listings coexist meanwhile
- C.App impersonation involves publishing a fake app with an identical or highly similar name, icon, and description to a popular legitimate app (banking app, email client); users who find the fake via search results or phishing download it and enter credentials, which are exfiltrated to the attacker's C2 server