Authenticator App Reportedly Uses App Store Advertising to Scam Users, Collects Secret QR Codes

Some copycat two-factor authenticator apps have annual subscriptions priced at up to $40 (roughly Rs. 3,300).

Advertisement
Written by David Delima, Edited by Siddharth Suvarna | Updated: 22 February 2023 14:33 IST
Highlights
  • Copycat two-factor authenticator apps have been spotted on the App Store
  • These apps can charge up to $40 (roughly Rs. 3,300) in annual fees
  • Users can opt for well-known apps from Google, Twilio for 2FA security

Two-factor authenticator apps can help users add a second layer of security to their accounts

Photo Credit: Unsplash/ Gilles Lambert

Authenticator apps like Authy and Google Authenticator help users add a second layer of security to their account, preventing malicious actors from accessing their personal information and data. Last week, Twitter announced that it would soon discontinue access to SMS-based two-factor authentication (2FA) for users who have not subscribed to the company's Twitter Blue service. Developers have now begun to flood the app store with authenticator apps that ask users to pay a subscription fee before they can add any accounts. 

Security company Mysk claims (via 9to5Mac) that there are several similar-looking authenticator apps that have recently been published to the App Store. Unlike Authy and Google Authenticator that allow users to scan QR codes to set up 2FA on their accounts, these applications first require users to sign up for a free trial that converts into a subscription priced as high as $40 (roughly Rs. 3,300) per year. Gadgets 360 was able to confirm that some of these apps with annual subscriptions are currently available on the App Store. 

Advertisement

In a separate tweet, the company also warns that at least one of these authenticator apps is running an advertising campaign on the App Store, and a screenshot reveals that it is the first app to show up  when searching for "authenticator". According to Mysk, this app sends the contents of the scanned QR code to the developer's Google Analytics service. This could result in the leaking of users' 2FA codes to the developer of the application. 

A screen recording shared by Mysk shows several similarly designed applications with very similar interfaces and prompts to subscribe to a $40/year annual plan. Developer Kevin Archer claims that these apps are being released with different metadata sets on new accounts, and seem to have skirted the guidelines enforced by the App Review team, including guideline 5.6.3 (Discovery Fraud), which does not permit manipulating App Store charts, search, reviews, or app referrals.

Advertisement

According to a screenshot posted by the company, many of the apps were released last week, which is around the same time that Twitter, which was recently taken over by Elon Musk, announced that it was dropping support for SMS-based 2FA for users who are not subscribed to its Twitter Blue service. Users who had set up their accounts to receive SMS login codes have until March to turn it off and set up third-party 2FA applications or hardware security keys to securely log in to their accounts. 

The existence of these apps on the App Store means that users who are looking to download 2FA apps on the App Store might end up downloading one of these applications, putting their security at risk. Apps like Google Authenticator, Authy, Aegis Authenticator (Android), and Microsoft Authenticator are secure and reliable options from reputable companies that can be used to store 2FA authentication tokens instead. 

Advertisement


5G is now available both on Android and iPhone in India. But is it any good? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy A27 Spotted in Leaked Mint Colourway, Might Launch Soon
  2. WWDC 2026: Tim Cook's Final Apple Keynote Marks the End of an Era
  3. Everything Announced at Xbox Games Showcase: Senua, Persona 6 and More
  4. Samsung Galaxy S27 Pro's Battery May Match the One on the Galaxy S26 Ultra
  5. New Leak Shows Us What Apple's Foldable iPhone Might Look Like
  6. OnePlus Turbo 6X Series Will Launch in China on This Date
  7. Infinix Smart 20 Launched in India With a 7.7mm Slim Body, Ultra Link Support
  8. Redmi Turbo 5 Confirmed to Launch in India With This Rear Camera Setup
  9. Vivo X300 FE, iQOO 15R and More Discounted During Amazon Mega Deal Days Sale
  10. Vivo V70 Lite 5G Silently Launched in Select Markets With These Features
  1. HTX Delists USD1 Stablecoin, Asks World Liberty Financial to Reverse Freeze on Exchange's Addresses
  2. Redmi Turbo 5 Confirmed to Launch in India With Identical Dual Rear Camera Setup as Chinese Variant
  3. OnePlus Turbo 6X Series Launch Date Announced Along With Key Specifications, Features
  4. WWDC 2026: Tim Cook’s Final Apple Keynote Marks the End of an Era
  5. Infinix Smart 20 Launched in India With MediaTek Helio G81 Ultimate SoC, Slim 7.7mm Profile: Price, Features
  6. Infinix Hot 70 Pro India Launch Timeline Leaked; Could Feature Dimensity 7100 Chip, 6,000mAh Battery
  7. Bitcoin Rebounds Above $62,000 as Buyers Return at Lower Prices Despite ETF Outflow Concerns
  8. Samsung Galaxy S26 FE WPC Database Listing Reveals Design, Qi2 Wireless Charging Support
  9. Apple's Foldable iPhone Seen in New Images of Dummy Units That Reveal Design
  10. Samsung Galaxy S27 Pro Leak Hints at Display Size, Tipped to Launch With 5,000mAh Battery
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.