{"id":51611,"date":"2026-04-16T15:52:00","date_gmt":"2026-04-16T19:52:00","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=51611"},"modified":"2026-04-28T10:53:19","modified_gmt":"2026-04-28T14:53:19","slug":"the-app-store-scammer-strikes-back","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2026\/04\/16\/the-app-store-scammer-strikes-back\/","title":{"rendered":"The App Store Scammer Strikes Back"},"content":{"rendered":"<p><a href=\"https:\/\/lapcatsoftware.com\/articles\/2026\/4\/2.html\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/lapcatsoftware.com\/articles\/2026\/4\/2.html\">\n<p>First, Virus Protection for Phone is <a href=\"https:\/\/apps.apple.com\/app\/virus-protection-for-phone\/id6736693162\">back in the App Store<\/a>! The App Store URL is the same, and the developer is the same, Virtual Advisors Limited. The app version history shows a large gap, with version 1.8 released in February 2025, before my blog post, and version 1.9 released just a few days ago. In retrospect, I have no way of knowing whether <em>Apple<\/em> removed the app from the App Store. The notoriously secretive corporation certainly didn&rsquo;t make any kind of statement. It&rsquo;s possible that the app developer voluntarily unpublished the app after noticing the bad publicity.<\/p>\n<p>The second update to the story is that the same scammer appears to have a second scam app in the App Store <a href=\"https:\/\/apps.apple.com\/app\/iphone-cleaner-virus-protect\/id6749690755\">iPhone Cleaner - Virus Protect<\/a> under a different developer account, Ranger Bookie Investments LLC. How did I discover this second app? The same way I discovered the first app: an advertisement on a sketchy video streaming website.<\/p>\n<p>[&#8230;]<\/p>\n<p>According to <a href=\"https:\/\/appfigures.com\/\">AppFigures<\/a>, iPhone Cleaner - Virus Protect had 65,000 downloads and an estimated net revenue of $310,000 worldwide over the last month. That&rsquo;s more money than I make in a year! I guess crime does pay.<\/p>\n<p>[&#8230;]<\/p>\n<p>For example, curiously, neither developer (they&rsquo;re surely one and the same developer) identifies as a trader in the European Union, despite the fact that both apps have In-App Purchases.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/thejollyteapot.com\/2026\/03\/16\/questions-about-the-future-of-macos-in-the-age-of-the-macbook-neo\/\">Nicolas Magand<\/a>:<\/p>\n<blockquote cite=\"https:\/\/thejollyteapot.com\/2026\/03\/16\/questions-about-the-future-of-macos-in-the-age-of-the-macbook-neo\/\">\n<p>Looking at the Top Free Apps list on the Mac App Store as I write this line, the 6th most popular app is called &ldquo;<a href=\"https:\/\/apps.apple.com\/fr\/app\/ai-chatbot%E3%86%8Dask-ai-anything-5-2\/id6753711999?l=en-GB&amp;mt=12\/\">AI Chatbot &middot; Ask AI Anything 5.2<\/a>&rdquo;. It sits right after Microsoft Excel and CapCut, and before Microsoft PowerPoint. No, this app&#x2009;&mdash;&#x2009;unrelated to OpenAI&#x2009;&mdash;&#x2009;is not fishy at all (!) and the Mac App Store is very safe. The 12th most popular app on the list is &ldquo;<a href=\"https:\/\/apps.apple.com\/fr\/app\/hp-print-and-support\/id1474276998?l=en-GB&amp;mt=12\">HP: Print and Support<\/a>&rdquo;. Great, great stuff.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.macrumors.com\/2026\/04\/14\/apple-mac-app-store-fake-crypto-wallet\/\">Juli Clover<\/a> (<a href=\"https:\/\/news.ycombinator.com\/item?id=47783278\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2026\/04\/14\/apple-mac-app-store-fake-crypto-wallet\/\">\n<p>A fake Mac app designed to look like the real thing snuck past Apple&rsquo;s app review team, costing users $9.5 million in cryptocurrency.<\/p>\n<p>According to <a href=\"https:\/\/www.coindesk.com\/business\/2026\/04\/14\/a-fake-ledger-app-on-the-apple-app-store-just-drained-usd9-5-million-in-crypto\"><em>CoinDesk<\/em><\/a>, a fake macOS version of the Ledger Live crypto wallet app scammed people into handing over access to their cryptocurrency wallets. More than 50 people fell victim to the fake app between April 7 and April 13.<\/p>\n<p>Ledger has an official Mac app, but it is distributed via the Ledger website and not through the <a href=\"https:\/\/www.macrumors.com\/guide\/mac-app-store\/\">Mac App Store<\/a>.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.macworld.com\/article\/3115356\/use-apples-app-store-at-your-own-risk.html\">David Price<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macworld.com\/article\/3115356\/use-apples-app-store-at-your-own-risk.html\">\n<p>With unhappy timing, news of this scam broke in the same week as the banning of Freecash, as reported by Macworld&rsquo;s sister site <a href=\"https:\/\/go.skimresources.com?id=111346X1569486&amp;xs=1&amp;url=https:\/\/techcrunch.com\/2026\/04\/14\/how-the-rewards-app-freecash-scammed-its-way-to-the-top-of-the-app-stores\/&amp;xcust=1-0-3115356-1-0-0-0-0&amp;sref=https:\/\/www.macworld.com\/article\/3115356\/use-apples-app-store-at-your-own-risk.html\">TechCrunch<\/a>. In adverts, Freecash offered to pay users to scroll on TikTok, but this was a flimsy veil for its real purpose: harvesting sensitive data. By installing and running the app, users were giving up data about anything from their religion to their sexual orientation, which the makers happily sold on to third parties.<\/p>\n<p>[&#8230;]<\/p>\n<p>That decision would appear to indicate that Freecash does not, contrary to its makers&rsquo; protestations, meet the standards of Apple&rsquo;s App Store. (The Android app is still showing up for me in Google search, but the URL it directs to no longer works. Presumably, then, it&rsquo;s been kicked off Google Play too.) But once again, it&rsquo;s unclear why Apple&rsquo;s vetting team wasn&rsquo;t able to spot this shortcoming <em>before<\/em> welcoming the app on to the company&rsquo;s official storefront. Or why it took so long to take action against an app whose murkier practices had been highlighted by journalists months previously.<\/p>\n<p>[&#8230;]<\/p>\n<p>This week has been unusually bad, but stories of this sort don&rsquo;t come as a surprise any more. The App Store of 2026 is absolutely stuffed with slop, scams, and clones, propped up by an ecosystem of fake reviews pushing undeserving apps to the top of the charts. Phil Schiller was complaining about <a href=\"https:\/\/www.macworld.com\/article\/676871\/phil-schiller-complained-about-insane-scam-apps-in-2012.html\">&ldquo;insane&rdquo; scam apps<\/a> 14 years ago, and to the casual eye it&rsquo;s difficult to see that things have got any better.<\/p>\n<p>[&#8230;]<\/p>\n<p>If running an app store is too much trouble, close it down. If comprehensive vetting is impractical, stop pretending the App Store is completely safe. (And definitely stop scaremongering about sideloading.) If you can&rsquo;t make the App Store a truly reliable resource for good, safe, legitimate software, then give iPhone users the freedom to install from other places. Or just stop pretending the App Store monopoly is about anything other than revenue.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/macworld-app-store-own-risk\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/macworld-app-store-own-risk\/\">\n<p>Price calls the App Store &ldquo;rotten&rdquo; &mdash; is there any other word? &mdash; and says Apple should &ldquo;give iPhone users the freedom to install from other places. Or just stop pretending the App Store monopoly is about anything other than revenue&rdquo; if it cannot effectively police its wares. I imagine Apple would argue it <a href=\"https:\/\/pxlnv.com\/linklog\/annual-fraud-prevention-headlines\/\">enforces its rules all the time<\/a> and sometimes things just get through.<\/p>\n\n<p>But that kind of response only reveals the scale of the store and, consequently, the problem: nobody can effectively govern this many items, especially when they are all user-submitted.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@lapcatsoftware\/116404586864749804\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@lapcatsoftware\/116404586864749804\">\n<p>Three scam apps I mentioned in my blog post are still in the crApp Store:<\/p>\n<p>Stronix VPN, Reliable VPN, Privacy Pro VPN<\/p>\n<p>Two mentioned apps are gone, but one already left and came back, so we don&rsquo;t know if it was Apple or the developer who removed them.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2026\/03\/02\/mac-app-store-review-times-increasing\/\">Mac App Store Review Times Increasing<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/05\/07\/free-with-in-app-purchase-is-a-sham\/\">Free With In-App Purchase Is a Sham<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/01\/22\/app-store-trader-status-deadline\/\">App Store Trader Status Deadline<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/04\/25\/virus-protection-for-phone\/\">Virus Protection for Phone<\/a><\/li>\n<\/ul>\n\n<p id=\"the-app-store-scammer-strikes-back-update-2026-04-17\">Update (<a href=\"#the-app-store-scammer-strikes-back-update-2026-04-17\">2026-04-17<\/a>): <a href=\"https:\/\/techcrunch.com\/2026\/04\/14\/how-the-rewards-app-freecash-scammed-its-way-to-the-top-of-the-app-stores\/\">Sarah Perez<\/a>:<\/p>\n<blockquote cite=\"https:\/\/techcrunch.com\/2026\/04\/14\/how-the-rewards-app-freecash-scammed-its-way-to-the-top-of-the-app-stores\/\">\n<p>When reached for comment, Almedia, the Germany-based company that owns Freecash, denied allegations of driving artificial traffic to its platform or using deceptive marketing techniques.<\/p>\n<p>&ldquo;Our apps are fully compliant with the Apple App Store and Google Play Store policies, as demonstrated by the fact that they are live and regularly pass platform reviews,&rdquo; an email from Almedia PR manager James Law, signed &ldquo;Almedia Press Office,&rdquo; noted.<\/p>\n<p>[&#8230;]<\/p>\n<p><a href=\"https:\/\/www.washingtonpost.com\/technology\/2021\/06\/06\/apple-app-store-scams-fraud\/\">A Washington Post report<\/a> about the scam app ecosystem noted this trend, highlighting several fraudulent apps that would disappear from the App Store and then reappear under a different developer account. Other independent <a href=\"https:\/\/lapcatsoftware.com\/articles\/2026\/4\/2.html\">investigations<\/a> have documented <a href=\"https:\/\/www.consumerreports.org\/customer-reviews-ratings\/hijacked-reviews-on-amazon-can-trick-shoppers\/\">this tactic<\/a> as well, and often, scam apps&rsquo; owners <a href=\"https:\/\/9to5mac.com\/2021\/02\/11\/app-store-scam-apps-how-to-spot\/\">operate a portfolio<\/a> of accounts, it&rsquo;s been reported.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/daringfireball.net\/linked\/2026\/04\/16\/freecash-was-more-like-scamcash\">John Gruber<\/a>:<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/linked\/2026\/04\/16\/freecash-was-more-like-scamcash\">\n<p>As I have <a href=\"https:\/\/daringfireball.net\/search\/bunco+squad\">repeatedly written<\/a>, it boggles my mind why Apple doesn&rsquo;t have an App Store &ldquo;bunco squad&rdquo; that targets scam and fraud apps <em>that are popular and\/or high-grossing<\/em>.\nIt&rsquo;s folly to think that the App Store could ever be completely free of scam apps. But it&rsquo;s absurd that this app Freecash rose to #2 in the App Store, with millions of downloads, and Apple only took a look at and removed it after TechCrunch asked about the app.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@peternlewis\/116417844376920283\">Peter N Lewis<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@peternlewis\/116417844376920283\">\n<p>There is no way Apple would fund a &ldquo;bunco squad&rdquo; whose sole job was to reduce Apple&rsquo;s revenue. They simply are not being hit by the consequences of the crap that is on the App Store. They are more than big enough and powerful enough to peddle the clearly false statement that the App Store keeps you safe, while making 30% off scamming victims and addicts, and people will continue to believe it&rsquo;s all good.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/appleinsider.com\/articles\/26\/04\/17\/app-store-scams-are-getting-worse-and-apple-isnt-doing-enough\">William Gallagher and Mike Wuerthele<\/a>:<\/p>\n<blockquote cite=\"https:\/\/appleinsider.com\/articles\/26\/04\/17\/app-store-scams-are-getting-worse-and-apple-isnt-doing-enough\">\n<p>We also know that this isn&rsquo;t new. But it is escalating, and getting far, far worse and more prevalent.<\/p>\n<p>[&#8230;]<\/p>\n<p>Apple cannot take a high ground and say only it can protect users, when it is not actually protecting them as well as it could and should.<\/p>\n<p>[&#8230;]<\/p>\n<p>It would unquestionably add to Apple&rsquo;s workload if it checked on an app a few hours or a few days after allowing such an update. But this is a known method that scammers use to get by the App Store review team.<\/p>\n<p>[&#8230;]<\/p>\n<p>After we reported less than four days ago about the fraudulent apps, Apple got back to us. They repeated the same talking points that they always do when an app gets pulled after it steals money from users, or some other nefarious deed. [&#8230;] Essentially the same email was sent to us 29 times over the last decade. The emails used verbatim quotes 17 times over that timespan.<\/p>\n<\/blockquote>\n\n<p id=\"the-app-store-scammer-strikes-back-update-2026-04-21\">Update (<a href=\"#the-app-store-scammer-strikes-back-update-2026-04-21\">2026-04-21<\/a>): <a href=\"https:\/\/medium.com\/@qinxilin\/the-mac-app-store-chatgpt-scam-four-apps-four-fake-developers-one-operation-68ae7f3f5c83\">Lin Xi Qin<\/a>:<\/p>\n<blockquote cite=\"https:\/\/medium.com\/@qinxilin\/the-mac-app-store-chatgpt-scam-four-apps-four-fake-developers-one-operation-68ae7f3f5c83\">\n<p>Three of the four apps offer &ldquo;lifetime&rdquo; subscriptions for $99.99, an economically impossible promise for any product whose ongoing cost scales with user activity. One of them links to a privacy policy that, on close reading, is a copy-paste from a completely unrelated app the same developer previously published. Another ships screenshots advertising &ldquo;AI Content Detector&rdquo; and &ldquo;Humanizer&rdquo; features that, by their nature, exist to evade OpenAI&rsquo;s own AI-detection tools &mdash; a direct violation of OpenAI&rsquo;s usage policy for its API.<\/p>\n<p>[&#8230;]<\/p>\n<p>What the HTTP capture shows is that the app presents users with a model selector containing GPT-5.4 and GPT-5.3 options &mdash; charges them premium subscription fees &mdash; and then, when they actually send a query, the code substitutes the cheapest model available and pockets the price differential as margin.<\/p>\n<p>This is not a trademark technicality. It is commercial fraud in the plain sense.<\/p>\n<p>[&#8230;]<\/p>\n<p>On March 30, 2026, <a href=\"https:\/\/thedailytechfeed.com\/new-clone-ai-chatbot-scam-on-macos-app-store\/\"><em>The Daily Tech Feed<\/em> published a technical investigation<\/a> of the first two apps &mdash; the Hira Amin &ldquo;5.4&rdquo; and the Hadiqa Bashir &ldquo;5.2.&rdquo; Their analysis, based on direct examination of the compiled binaries and captured network traffic, documents that the two apps are not independent products from independent developers. They are duplicated instances of the same underlying software, distributed through two separate Apple developer accounts.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/eclecticlight.co\/2026\/04\/19\/last-week-on-my-mac-dont-be-a-victim-of-fraud\/\">Howard Oakley<\/a>:<\/p>\n<blockquote cite=\"https:\/\/eclecticlight.co\/2026\/04\/19\/last-week-on-my-mac-dont-be-a-victim-of-fraud\/\">\n<p>Finally, never misinterpret claims made of an app&rsquo;s credentials. Although every App Store app is reviewed by Apple, experience has shown that&rsquo;s far from being a reliable protection from fraud.<\/p>\n<p>[&#8230;]<\/p>\n<p>I&rsquo;m afraid that when it comes to checking potentially fraudulent apps, you&rsquo;re still responsible for making your own decisions. Please choose wisely.<\/p>\n<\/blockquote>\n\n<p id=\"the-app-store-scammer-strikes-back-update-2026-04-28\">Update (<a href=\"#the-app-store-scammer-strikes-back-update-2026-04-28\">2026-04-28<\/a>): <a href=\"https:\/\/thehackernews.com\/2026\/04\/26-fakewallet-apps-found-on-apple-app.html\">Ravie Lakshmanan<\/a> (<a href=\"https:\/\/x.com\/TheHackersNews\/status\/2047644932580818945\">tweet<\/a>):<\/p>\n<blockquote cite=\"https:\/\/thehackernews.com\/2026\/04\/26-fakewallet-apps-found-on-apple-app.html\">\n<p>The 26 apps, collectively dubbed FakeWallet, mimic various popular wallets like Bitpie, Coinbase, imToken, Ledger, MetaMask, TokenPocket, and Trust Wallet. Many of these apps have since been taken down by Apple following disclosure. There is no evidence that these apps were distributed via the Google Play Store.<\/p>\n<p>[&#8230;]<\/p>\n<p>These apps have icons that mirror the original but have intentional typos in their names (e.g., LeddgerNew) so as to trick unsuspecting users into downloading them. In some cases, the app names and icons have no connection to cryptocurrency. Instead, they are used as placeholders to direct users to download the official wallet app through them, claiming they are &ldquo;unavailable in the App Store&rdquo; due to regulatory reasons.<\/p>\n<p>Kaspersky said it also identified several similar apps likely linked to the same threat actor that do not have the malicious features enabled, but have been found to mimic a benign service, such as a game, a calculator, or a task planner. Once launched, these apps open a link on the web browser and leverage enterprise provisioning profiles to install the wallet app on the victim&rsquo;s device.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Jeff Johnson: First, Virus Protection for Phone is back in the App Store! The App Store URL is the same, and the developer is the same, Virtual Advisors Limited. The app version history shows a large gap, with version 1.8 released in February 2025, before my blog post, and version 1.9 released just a few [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2026-04-16T19:52:05Z","apple_news_api_id":"87549349-5fd3-4975-ba2d-f762339e05c7","apple_news_api_modified_at":"2026-04-28T14:53:26Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAABA==","apple_news_api_share_url":"https:\/\/apple.news\/Ah1STSV_TSXW6LfdiM54Fxw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[91,2036,914,31,2741,30,39,2742,158],"class_list":["post-51611","post","type-post","status-publish","format-standard","hentry","category-technology","tag-appstore","tag-app-store-scams","tag-bitcoin","tag-ios","tag-ios-26","tag-mac","tag-macappstore","tag-macos-tahoe-26","tag-strategytax"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/51611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=51611"}],"version-history":[{"count":6,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/51611\/revisions"}],"predecessor-version":[{"id":51731,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/51611\/revisions\/51731"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=51611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=51611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=51611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}