AntiMalwareJuly 14, 2026🇷🇺Translated from Russian

Generative AI Can Clone and Modify Android Apps for as Little as 88 Kopecks, Positive Technologies Warns

Specialists at Positive Technologies have shown that modern generative AI systems can rapidly create functional clones of Android applications at minimal cost, significantly lowering the entry threshold for potential attackers.

In a controlled experiment, researchers tested 90 popular applications across multiple categories. Instead of injecting malicious code, they instructed the AI models to make neutral modifications, reassemble the APK packages, and verify whether the altered apps remained operational. The results proved concerning for the security community.

Closed commercial models successfully completed the task in 84% of attempts, while models with open weights achieved a 61% success rate. On average, the AI required 14 iterations and between five and a half to nine minutes to produce a working modified version. The final cost per successful outcome ranged from 0.88 to 40.89 rubles, depending on the model and number of attempts.

These figures imply that a determined actor could attempt to modify approximately one hundred widely used applications for only a few thousand rubles. In real-world scenarios, the same process could be used to insert data-stealing functionality, change application behavior, or establish communication with external servers controlled by attackers.

The resulting counterfeit builds are easy to promote as official updates, improved versions, or applications unavailable in the Google Play store. Distribution channels include third-party app catalogs, websites, messaging platforms, and specialized online communities. Users who regularly sideload APK files from untrusted sources are particularly exposed.

Lowering the Barrier for App Modification Attacks

Positive Technologies emphasizes that generative AI has not invented a fundamentally new attack technique. Instead, it has automated and accelerated the labor-intensive process of reverse engineering and code modification that previously demanded considerable time and specialized expertise.

Developers are advised to implement stronger code protection mechanisms against analysis and tampering, actively monitor the appearance of unofficial builds, and integrate security considerations from the earliest stages of application design. Without such measures, malicious clones may appear faster than legitimate teams can release patches.

Related articles

HabrOther

Oxygen Cloud Platform Deploys Russian VDI Solution for Heavy 3D CAD Work in One Month

Oxygen Cloud Platform completed a rapid deployment of a domestic VDI infrastructure supporting demanding 3D graphics workloads for an unnamed Russian engineering company. The project replaced six months of prior R&D testing with a one-month rollout using Russian operating systems, hypervisors, and connection protocols. Engineers addressed GPU sharing via Forsite vGate, optimized NVIDIA A40 cards for Siemens NX and Kompas-3D, and resolved multi-monitor detection issues through firmware updates. Network latency was mitigated by tuning the Loudplay protocol and updating Astra Linux, Termidesk, and client components. Automatic resource brokering was configured in Termidesk with separate Active Directory pools to handle varying user profiles across remote sites 1500 km away. The solution delivers protected access to a secure data center over a dedicated channel while meeting strict import-substitution requirements.

HabrOther

MEPhI Opens 2026 Admissions for Online Cybersecurity Master's Program with Yandex Practicum

The National Research Nuclear University MEPhI, in partnership with Yandex Practicum, is accepting applications for its online master's program in Cybersecurity for the 2026 intake. The two-year program leads to a state diploma in Information Security under code 10.04.01 and a professional retraining certificate from Yandex Practicum. Students can choose from four specialized tracks covering AppSec, DevSecOps, network security, and AI security. Admission is fully online and includes document submission via Gosuslugi, an entrance exam, and a motivation letter requiring at least 80 points. The program runs entirely remotely with evening and weekend classes, allowing students to combine studies with work while accessing student benefits and an educational loan at a subsidized 3% rate.

安全客Other

360 Group Launches NanoWork Enterprise AI Platform with Built-in Security and Opens Nationwide Channel Partner Recruitment

On July 28 at the Beijing National Convention Center, 360 Group founder Zhou Hongyi officially unveiled NanoWork, a next-generation enterprise intelligent agent work platform. The platform is designed to bridge the gap between powerful AI models and real-world business tasks by enabling multi-agent collaboration, on-demand model scheduling, and 24/7 cloud operation across diverse scenarios. NanoWork was developed through extensive real-world testing involving 100,000 intelligent agents, coverage of 630 positions over 150 days, consumption of 350 trillion tokens, and collection of 56,000 feedback items. A core emphasis is placed on native security features drawn from 360 Group's two decades of cybersecurity experience to prevent errors that could lead to actual data loss or permission breaches. The company is now actively recruiting city-level channel partners across China to help deploy the solution in local industries and activate existing customer bases with AI capabilities.

AntiMalwareOther

Google Enables Document Backup to Drive in Stable Play Services 26.26 Release

Google has rolled out automatic document backup from Android devices to Google Drive in the stable version of Google Play Services 26.26. The feature, which the company prepared for nearly a year, adds a new Documents option in Settings on Pixel phones under Accounts and backup. It remains disabled by default to avoid uploading the Downloads folder without user consent. Once enabled, supported files including PDF, DOC, PPT, XLS, ZIP and even APK files are copied to a new Android backups folder on Drive, with separate subfolders created for each device. The backup consumes storage quota and offers no automatic two-way sync, requiring manual cleanup when disabled. Traces of the capability first appeared in August 2025, followed by an official mention in February 2026 and beta testing before the current stable deployment.