Which attack involves taking a legitimate mobile game and adding malware before uploading to a third-party app store?

Prepare for the Certified Ethical Hacker Version 11 Exam with a comprehensive test featuring flashcards and multiple choice questions, each accompanied by hints and explanations to ensure a thorough understanding. Ace your ethical hacking exam with confidence!

Multiple Choice

Which attack involves taking a legitimate mobile game and adding malware before uploading to a third-party app store?

Explanation:
Repackaging legitimate apps is about taking a real mobile game, injecting malware into its package, and uploading the altered version to third-party app stores. This leverages the trust users place in a familiar game—the app appears legitimate, making it easier for users to install without suspicion. The attacker relies on distributing through stores that may have weaker vetting, increasing the chance the malicious repackaged app is downloaded. This fits the scenario precisely because it starts with a genuine game and ends with a malicious version being distributed. The other options describe different attack methods: SMiShing uses malicious SMS-based phishing, pretexting is a social-engineering tactic to obtain information, and publishing malicious apps could involve creating a malicious app from scratch rather than tampering with a legitimate one.

Repackaging legitimate apps is about taking a real mobile game, injecting malware into its package, and uploading the altered version to third-party app stores. This leverages the trust users place in a familiar game—the app appears legitimate, making it easier for users to install without suspicion. The attacker relies on distributing through stores that may have weaker vetting, increasing the chance the malicious repackaged app is downloaded.

This fits the scenario precisely because it starts with a genuine game and ends with a malicious version being distributed. The other options describe different attack methods: SMiShing uses malicious SMS-based phishing, pretexting is a social-engineering tactic to obtain information, and publishing malicious apps could involve creating a malicious app from scratch rather than tampering with a legitimate one.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy