End-to-end mobile security provider Approov today released a report showing that 95 percent of the most popular African banking and financial services apps contain easy-to-extract secrets, which could be used in scripts and bots to attack application programming interfaces (APIs) and steal data, devastating consumers and the institutions they trust.
The research was conducted by a team from the CyLab-Africa and Upanzi Open Digital Technologies Network initiatives in and sponsored by Approov: 224 financial Android applications were selected from countries in North, Central, Eastern, Western and Southern Africa, and were downloaded and investigated.
CyLab-Africa, located in Kigali, Rwanda, is a collaboration between Carnegie Mellon University’s CyLab Security and Privacy Institute and Carnegie Mellon University Africa. Upanzi is an Africa-based network of research labs that focuses on creating, testing, innovating and assisting in implementing digital technologies at scale, such as identity, payments, cybersecurity, cloud computing, data governance, artificial intelligence and machine learning, and influencing technology policy recommendations to support the digital transformation of low- and middle-income countries (LMICs).
The study draws comparisons between other regions and Africa, pinpointing trends, commonalities, and disparities pertaining to the exposure of secret keys in a mobile application’s binary package.
Notably, 18% of the apps investigated revealed high severity secrets. A high severity classification was used for vulnerabilities that could potentially lead to unauthorized access, data breaches, and compromised user privacy. These apps together constitute a total of 272 million downloads across the continent with 72% of the apps revealing medium severity secrets that encompass sensitive data. If exposed, they could potentially compromise the confidentiality of user data and application functionality. (Key findings are listed below).
The World Economic Forum analyzed the enormous importance of mobile financial apps across Africa, in its March 18, 2022 briefing: Mobile payment in Africa is more popular than you may think – here’s why. It’s worth remembering that landlines are comparatively scarce and there are over 650 Million users of mobile devices – more than in either the USA or EU.
The keys found in the reverse engineered Android Application Packages (APKs) include:
- encryption keys for securing sensitive data
- authentication keys for accessing services
- signing keys for verifying data authenticity
- database credentials
- OAuth client secrets
- push notification keys
- code push keys
- payment gateway secrets
- encryption initialization vectors
- license keys
- sensitive configuration setting
Key findings:
- 95% of fintech apps across Africa immediately expose valuable, exploitable secrets.
- Approximately 272 million users have downloaded apps that inadvertently reveal sensitive, high-risk secret keys.
- Crypto was the most exposed type of app, with 33% of crypto apps found to expose high severity secrets.
- Apps deployed in West Africa were the most exposed in terms of high severity secret exposure and Southern Africa the least: 20% of apps in West Africa exposed such secrets versus only 6% in Southern Africa.
- Google Cloud API keys were identified in 86% of the examined applications. Such exposure can lead directly to accounts being compromised.
- Approximately 15.3% of the apps exposed various authentication tokens, including Facebook authentication tokens.
The full report can be downloaded here.

Approov Identifies & Addresses Apple Watch Security Issues
Posted in Commentary with tags Approov on December 19, 2023 by itnerdApproov, the leader in mobile security, today revealed new data indicating that watches, wearables and new devices are now the weakest link in the mobile app threat landscape.
Key findings include:
The findings were released in today’s Approov blog “Approov Addresses Apple Watch Security Issues” at this link: https://approov.io/blog/apple-watch-security-issues
Apple and MIT recently published a study indicating that 2.6 billion personal records were exposed through data breaches over the last two years. These findings underscore the need for protecting data in the cloud through mobile attestations and improved API security.
Approov, a trailblazer in mobile app and API security, addresses this threat directly with Release 3.2. The release introduces groundbreaking features, including the first commercially available App Attestation Solution for Apple WatchOS to provide API Protection against emerging threats.
The release also includes Harmony OS support and deployment of extended global Points of Presence (PoPs), and improved ease of deployment and administration.
Approov’s Runtime Application Self Protection (RASP) defenses are also strengthened by extending threat detections to include the latest versions of tools used by hackers to attack apps and APIs.
The danger is real: In September, Citizen Lab found an actively exploited zero-click Apple vulnerability which was used to deliver NSO Group’s Pegasus mercenary spyware. Apple acknowledged the threat to all their devices, issuing a specific WatchOS Security briefing (https://support.apple.com/en-mide/106360) on November 9 concerning a vulnerability in Apple Wallet on WatchOS. Apple quickly released a fix but acknowledged that “A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited”.
Approov now extends all the protections available on mobile apps to WatchOS. Approov support of WatchOS allows direct registration of WatchOS apps and ensures API protection against malicious traffic that is communicating directly from the watch to the cloud. WatchOS support is added to the existing support for Android Wearable Devices (which has been available since Version 3.0)
Approov Adds Huawei HarmonyOS Support: A Global Imperative
As a widely adopted operating system in regions such as China, India, the Middle East, and Africa, HarmonyOS plays a crucial role in the global mobile ecosystem. Recognizing the prevalence of this platform, Approov now ensures that mobile applications operating on Huawei devices are seamlessly integrated into our attestation services.
Approov attestation services traditionally supported Android and iOS devices, but the inclusion of Huawei HarmonyOS significantly broadens our platform coverage. This expansion is vital to offering a truly global solution, as any unattested mobile application poses a potential risk to API security, regardless of its geographical origin.
In collaboration with Cylab-Africa, Approov reinforces its commitment to a global solution for mobile app security. Version 3.2 extends support for Huawei app store deployments, catering to developers worldwide.
Enhanced High-Performance Worldwide Coverage
Approov expands its global network with new Points of Presence in São Paulo, Brazil and Singapore. These additions, coupled with existing points of presence (PoPs) in Europe (Dublin) and North America (California), create a worldwide low-latency mobile attestation network.
This move bolsters Approov’s commitment to achieving new levels of security by mitigating bot attacks, Man-in-the-Middle (MitM) attacks, account takeover (ATO) and other threats to mobile APIs, thus ensuring optimal performance and reducing fraud and data breaches.
New Threats are Addressed
The new release also boosts Approov’s RASP feature set to include new countermeasures against emerging and evolving threats. This includes significant hardening improvements to the SDK, including static and dynamic anti-tamper measures. Additionally, Approov’s ThreatLabs have developed further Android based detections for DobbyHook, Magisk, Zygisk, and Zygisk-Frida to fortify defenses against these advanced hacker tools. These changes augment the comprehensive suite of detections that are already implemented. In addition, the dynamic security-policy update facility will be used to improve the detection capabilities of existing deployed apps that currently use Approov’s previous SDKs.
Increased Ease of Use for DevOps/Developers
Approov continues to focus on easing the security burden for developers, DevOps and DevSecOps teams. New features simplify app registration and management, providing an automated and streamlined integration experience. The elimination of the need for individual app registrations and the introduction of tools for managing different app versions reduce complexity. Approov also enhances the registration of developer devices for testing, ensuring a secure and efficient device farm testing process.
Approov Mobile App and API Security Software Release 3.2 reaffirms the Company’s commitment to continued innovation in order to ensure there are no weak links for its customers.
Upgrades to Approov Version 3.2 will be included as part of Approov’s Software-as-a-Service Mobile Security platform. New customers can embrace the future of mobile app and API security by starting a free 30-day trial by registering at Approov.io.
Leave a comment »