A great running gag in the American comedy classic “Coming to America” is McDowell’s, a fast-food restaurant in Queens, NY, that’s an obvious rip-off of McDonalds, complete with golden arches (“Golden Arcs,” owner Cleo McDowell would correct you). Instead of the Big Mac, McDowell’s offers the exact same as the Big Mick… Except no sesame seeds on the bun.

In digital media, running into spoofed websites, apps, and app stores is an unfortunately common occurrence, and definitely not humorous in the least bit for security, marketplace quality, and ad ops professionals.

Which is why The Media Trust has been particularly alarmed by the rise in advertising clicking through to third-party app stores that spoof the environments of major digital marketplaces like Apple’s App Store and Google Play. We’ve created a new Threat Type called Fake App Store — this new type will enable clients to action this specific issue while keeping it separate from other threats.

Threat or Not?

While not all third-party app stores mimicking known marketplaces are necessarily malicious, they should be approached with caution as they are clearly trying to mislead consumers. Spoofed domains have long been used for phishing attacks and the distribution of backdoors that can deliver credential scrapers, ransomware, and more.

But the app space can be different — apps could choose a third-party app store rather than (or even in addition to) Apple’s App Store or Google Play. First off, they may be trying to avoid Apple and Google’s large revenue commissions, or trying to get around these marketplace’s strict rules around content, pricing, payment systems, gambling, and more. Third-party app stores also make more sense in certain geos (e.g., China) and allow more freedom in terms of updates and offerings.

Still, it’s concerning when an app store tries to make itself look like a well-known marketplace. That speaks to a desire to mislead consumers, which is something that The Media Trust cannot ignore.

Introducing New Threat Type Fake App Store

Here’s the description for our new threat type, Fake App Store, which appears in the TMT UI and reports:

The landing location for this ad leads to a digital marketplace that mimics the aesthetics of well-known, legitimate digital storefronts for purchasing and downloading software applications — e.g., Apple’s App Store or Google Play. Not only is the advertiser trying to mislead consumers about the landing destination, the use of such Fake App Stores also suggests that the advertised app itself may be of questionable quality or even a security risk. 

We hope this is a valuable addition to keep consumers safe, maintain a reputation for high-quality, and of course — drive revenue. If you’d like to know more about this threat type as other ways The Media Trust looks out for the safety of consumers and your business, fill out the form below and we’ll get right back to you.

What is the Fake App Store malvertising campaign? 

The Fake App Store campaign is a malvertising technique that redirects users from online advertisements to fraudulent app store pages that imitate legitimate platforms. These fake stores are designed to trick users into downloading malicious apps or providing sensitive information.

Attackers use deceptive ads, redirects, and convincing web pages that closely resemble trusted app stores. Once users arrive, they may be prompted to install a fake application, approve excessive permissions, or enter login credentials, exposing them to malware or phishing attacks.  

Fake app stores exploit users’ trust in familiar brands and interfaces. By copying the look and feel of legitimate marketplaces, attackers reduce suspicion and increase the likelihood that users will download malicious software or share personal information. 

Installing applications from fraudulent sources can lead to malware infections, credential theft, financial fraud, unauthorized device access, and the compromise of personal or business data.  

These campaigns impact consumers, publishers, advertisers, ad tech platforms, mobile app developers, and brands. Users face the risk of malware and phishing, while organizations may experience reputational damage, loss of customer trust, and increased security incidents. 

Malicious advertisements serve as the entry point for these attacks by redirecting users to counterfeit app store pages. Because the ads often appear on legitimate websites, users may not realize they are interacting with a fraudulent destination. 

Organizations should continuously monitor advertising creatives, inspect landing pages, detect malicious redirects in real time, and enforce strict ad quality controls across the advertising supply chain. Proactive threat detection helps prevent malicious campaigns from reaching users. 

Common indicators include unusual URLs, unfamiliar developer names, poor grammar, unexpected permission requests, requests to sideload applications, and download pages that differ from official app store experiences.  

Fake app store campaigns can change domains, landing pages, and payloads rapidly to evade detection. Real-time monitoring enables organizations to identify malicious behavior quickly and block threats before users are exposed. 

The campaign demonstrates how cybercriminals continue to combine malvertising, phishing, and brand impersonation to exploit user trust. Protecting users requires continuous ad monitoring, rapid threat detection, and strong digital trust and safety practices across the advertising ecosystem.

The Fake App Store campaign is a sophisticated malvertising attack that uses deceptive advertisements to direct users to convincing fake app store pages designed to mimic trusted platforms. Instead of sending users to legitimate download sources, attackers create fraudulent storefronts that encourage victims to install malicious applications or disclose sensitive information. The campaign combines social engineering, brand impersonation, and realistic user interfaces to increase credibility and evade detection. The analysis explains how the attack works, why fake app stores are an effective phishing technique, the risks to publishers and advertisers, and the importance of proactive ad monitoring and real-time threat detection to stop malicious campaigns before they reach users.