Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-21 · updated: 2026-09-21 · tags: [incident, global, android, phishing] · confidence: high · severity: medium · affected_sectors: [global] · au_impact: false

Researchers at the University of Massachusetts Amherst analysed 61,500 abandoned Android IoT companion apps — the apps used to control smart plugs, cameras and thermostats — and found nearly three in four contained software dependencies associated with documented vulnerabilities, most in the higher severity tiers. The dataset was built from AndroZoo, with an app classed as abandoned if it had gone two years without an update or been delisted from Google Play by March 2025. Abandonment did not mean small audiences: most apps had thousands of installs, and a dozen had passed 100 million downloads before development went quiet. The code carried thousands of hardcoded web addresses, and about a quarter of the unique domains no longer resolve. A scan against threat-intelligence blocklists matched roughly one in nine extracted addresses, with hundreds of exact matches for phishing, scam, spyware and malware links, and more than two-thirds of apps contained at least one blocklisted domain. A check of domain registration history found that a modest share of still-active domains had changed hands since the app was last updated, affecting over 2,000 apps — the classic abandoned-endpoint takeover path — and the researchers note that users expect IoT devices to stay in service for about a decade, far beyond vendor maintenance commitments for the phone app that controls them.

Attribute Detail
Sector Global (Macro)
Date 2026-09-21
Source Help Net Security
Reliability Tier 3