Sideloading from Unofficial App Stores – Why Do We Do It?

Appstore Vs Playstore

Last updated 11 August 2026

Is a free app worth the risks?

For most users, installing an app is a simple safe process that involves downloading a file from their app store. However, there is an alternative to the official Apple App Store or Google Play Store which presents serious third party app store risks.

‘Sideloading’ is the process of downloading and installing apps onto a mobile device from an unofficial source. On Android, users enable device settings to download apps from unknown sources. On iOS, users had to jailbreak their device to sideload. More recently, hackers have used fraudulent or stolen enterprise app certificates to distribute unofficial apps. However, many users remain unaware of the potential risks involved in using this technique.

It was reported last year that over 50 times more malware came from internet-sideloaded sources than on apps available through Google Play. Also, numerous reports have found trojans, spyware, click fraud and phishing code hidden within unofficial apps. If installed on a mobile, they could pose danger to the security of the device.

So let’s have a closer look at sideloading. How does it work? What are the potential risks? And, despite these risks, why do so many people continue to download their apps from unofficial app stores?

What is sideloading?

Sideloading involves manually downloading and installing an app from an installer file outside of an official app store. There are two distinct ways that users achieve this on Android and iOS devices.

For Android, sideloading used to require the user to simply tick a box in their device settings. This would enable the download of an app .apk file from an ‘unknown source’, i.e. not Google Play Store. Therefore, its security feature, Google Play Protect, couldn’t vet the app. More recently, Google has continued to tighten how sideloading works on Android, adding more friction and enforcement around installing apps outside of Google Play. As ZDNET reports, the company’s newer measures are designed to limit risky installs and push users toward safer distribution channels; meaning sideloading is still possible, but it increasingly comes with extra warnings, checks, and potential blocks.

Those measures now have dates attached. From September 2026, apps from unverified developers will stop installing on certified Android devices, beginning in Brazil, Indonesia, Singapore and Thailand, with other countries to follow. Developers who want their apps to keep working outside Play must register with Google, which means a fee and government identification, or use a free limited distribution account capped at 20 devices.

Users who want to opt out of the requirement can do so through what Google calls its advanced flow, available from August 2026, though only after a deliberately slow process that begins with enabling developer mode by tapping the build number seven times. Reporting on the flow indicates it takes more than 24 hours to complete, and the install prompt still warns that the developer is unverified.

Google has been open about why it built that delay in. The flow is designed to resist coercion, so that a user cannot be talked through it in real time by a criminal working under time pressure. In the scenario Google describes, a caller impersonating a bank tells the victim their account has been compromised and walks them through installing an app that will supposedly protect their money, pressing them to ignore each warning as it appears. The app then harvests their login credentials and intercepts the two-factor codes protecting the account.

For iOS, there have also been changes to how mobile users access unofficial apps. Reporters revealed that several rogue marketplaces, dubbed ‘DarkSideLoaders’, have made it possible to download millions of apps for non-jailbroken iOS devices. As we previously reported, app developers have discovered a way to use Apple’s Enterprise Developer program to distribute apps outside of the app store. The process involves posing as a legitimate business to obtain an Apple Enterprise App certificate. In fact, years ago, TechCrunch uncovered more than a dozen hardcore pornography and real-money gambling apps as well as modified versions of popular iOS apps such as Spotify, Angry Birds and Minecraft developed under this program and available for download independent of the App Store.

Outside the EU and Japan, those remain the only routes onto an iPhone. Within them, sideloading is now lawful and supported by Apple itself. The company resisted this for years, arguing in its 2021 threat analysis Building a Trusted Ecosystem for Millions of Apps that opening the platform would leave iPhones as exposed as PCs. Regulation overrode that position. Under the Digital Markets Act, users in the EU can install apps from alternative app marketplaces and directly from authorised developers’ websites, with AltStore PAL, Epic Games Store, Setapp Mobile and Aptoide among those now operating. Japan’s Mobile Software Competition Act took effect on 18 December 2025 and requires the same, with Apple shipping the necessary changes that month.

Apple does retain a check on what gets through. Every iOS app distributed in the EU, including through a rival marketplace, must still be notarised, meaning Apple scans it for malicious code and code-signing issues and can block it if it fails. Notarisation is a narrower test than full App Review, and each marketplace applies its own approval policies on top of it.

Unofficial app stores contain malware threats

What are the risks?

The volume of malicious software reaching devices outside the official stores is the clearest measure of the problem. Google Play Protect now scans over 350 billion apps a day across both Play and other sources, up from 200 billion the year before. In 2025 its real-time scanning identified more than 27 million new malicious apps sourced from outside Play, against 13 million in 2024 and 5 million in 2023. Its enhanced fraud protection, which now covers 2.8 billion devices across 185 markets, blocked 266 million risky installation attempts involving 872,000 distinct applications.

Inside Play, the same year saw more than 1.75 million apps rejected for policy violations, over 255,000 blocked from excessive access to sensitive user data, and every submission run through more than 10,000 safety checks before publication. That contrast is the argument in a sentence. Apps that go through a store meet a series of gates. Apps that do not, meet none.

Kaspersky’s telemetry points the same way, with detected Android threats growing by almost half in 2025 and banking trojans rising close to fourfold globally.

How the attack actually works

Malicious sideloaded apps rarely announce themselves at installation. The pattern that recurs across current campaigns has four stages.

A message arrives, and it is usually a message rather than a search. Kaspersky finds that malicious installation packages now travel mainly through messaging apps, dropped into direct messages and group chats with a file name chosen to look harmless and a note explaining how to get past the operating system’s warnings. Once a device is infected, the malware often forwards itself to everyone in the victim’s contacts.

The first app installed is a decoy. It presents itself as something ordinary and asks for a permission that sounds necessary for it to function, most often Accessibility, then uses that access to fetch and install the real payload. The OverlayPhantom trojan documented by Cyble researchers arrives disguised as either a national government identity app or TikTok, and prompts the user to accept what looks like a routine system update.

The payload then waits and watches. Accessibility permissions let it see which app is in the foreground, so it can detect the moment a banking or payment app opens and place a convincing fake login screen over the real one. OverlayPhantom targets more than 180 banking, financial services and cryptocurrency applications across ten countries, the United Kingdom among them.

Finally it resists removal, and it goes after the controls meant to stop it. Variants hide themselves from the app drawer, interfere with system navigation to make uninstallation difficult, and attempt to disable Play Protect outright.

For an organisation, the stage that matters most is the interception of one-time codes. Reading the screen in real time and capturing SMS allows an attacker to walk through multi-factor authentication, which turns a compromised personal handset into a working route to corporate email, files and single sign-on.

So why do people use unofficial app stores?

We have found that there are four main reasons.

It’s free

The biggest reason seems to be a simple one: users want to download content without paying for it. Many third-party marketplaces offer games, wallpapers and utilities for nothing, along with modified versions of well-known apps that strip out the advertising or the subscription. Children particularly find this type of content attractive. Unofficial apps can also give users access to free streamed films, television and music. Piracy-adjacent sites remain a dependable place for attackers to plant malicious installers, because visitors arrive already expecting to click past a warning.

Location restrictions

Users may also turn to unofficial app stores to get around geographical restrictions of content. Often, developers only release apps or other media to select regions initially. This means that people living in other locations must wait months to access the content. For example, events like Game of Thrones’ final season made it extremely important for people to access content as it was released to avoid spoilers and stay up-to-date with the latest cultural phenomena.

Geographical restriction has since broadened well beyond release windows. Apps are now withheld from particular countries for regulatory reasons, withdrawn from markets entirely, or gated behind age verification requirements. Each of those creates a population of users looking for another way in.

It’s the only option

The third reason is simply that it is the only way that users can access the content. In 2018, Fortnite, the hugely popular online video game announced that it would be made available for download to Android devices but with a catch. Instead of downloading via Google Play Store, users would need to sideload the game’s .apk file from developer Epic Games’ website. In situations like this, users potentially leave themselves vulnerable to compromise.

That particular standoff has since been settled by regulators and courts rather than by the platforms. Epic now runs its own store on iOS in the EU and Japan, and following the injunction in Epic’s case against Google, rival app stores began appearing inside the US Play Store from 22 July 2026. The wider effect is that installing software from somewhere other than Play or the App Store is becoming an ordinary thing for a user to do, which makes it a much weaker signal that something is wrong.

Sideloading from Epic Games

Source: Epic Games

Somebody told them to

The fourth reason is the one now doing most of the damage, and it is the reason Google gave for building delay into its advanced flow. The user is not looking for an alternative app source at all. They are following instructions in a message or a phone call that appears to come from their bank, a courier, a government service or a recruiter. Every technical control in the chain works exactly as designed, and the user overrides all of them, because somebody credible has told them the warnings are the problem.

What this means for security teams

Blocking installation from unknown sources through MDM is worth doing on managed devices, and platform enforcement from September 2026 will handle some of this automatically. Neither closes the gap. Policy controls do not extend to BYOD, where most of this risk sits. They do not cover the legitimate alternative marketplaces that users in the EU and Japan can now install from. They give no visibility into what was installed before a control was applied, and they do nothing about an app the user was talked into approving.

What remains reliable is behaviour. A malicious app is quiet at the point of installation and busy afterwards, because it has to reach its command and control infrastructure to collect its payload, take instructions and send back what it captures. That traffic is the earliest dependable indication that something has gone wrong on a device, and frequently the only one available before credentials or money move.

Which is the question worth putting to your own organisation. If an employee installed one of these apps this afternoon, on a personal phone that reads corporate email, how long would it take you to know?

Book a demo to see how Corrata answers that.

Frequently asked questions

What is sideloading?

Sideloading means installing an app from a source other than the device’s official app store. On Android that means an .apk file from a third-party store or a website. On iOS it used to mean jailbreaking the device or abusing an Apple enterprise developer certificate, and in the EU it now also covers authorised alternative marketplaces and downloads from a developer’s own website. What these routes share is that the app has not been through the review the official store applies.

Is sideloading safe?

It carries higher risk, and Google’s own reporting has consistently found that devices installing from outside the Play Store are more likely to end up with a harmful app. Trojans, spyware and phishing code are the payloads found most often in unofficial apps. Some checking does still happen. Play Protect scans apps on certified Android devices whatever the source, and Apple notarises every iOS app in the EU regardless of channel. Both are lighter than full store review, and neither is a substitute for it.

Can you sideload apps on an iPhone?

In the EU, yes. Since iOS 17.4, Apple has supported alternative app marketplaces and direct downloads via Safari on iPhones in the EU, and the European Commission has confirmed this covers both third-party app stores and downloads from a developer’s own website. The change is geofenced to EU users, so UK iPhones are not covered. Outside the EU, installing an app from another source means jailbreaking, abusing an enterprise certificate, or self-signing the app with a developer account, which has to be repeated every few days.

Why do people sideload apps when the risks are known?

Three reasons come up repeatedly. The app or content is free when the official version is paid. The official release is geographically restricted and the user does not want to wait. Or sideloading is the only route, as it was when Epic Games distributed Fortnite for Android from its own website rather than through Google Play. In each case the security trade-off is not visible to the user at the point of installing.

How can an organisation stop employees sideloading apps on work phones?

Policy alone does not hold, because the same device is used personally. Mobile device management can block installation from unknown sources on managed Android, but it does not cover personally owned devices in a BYOD estate. What closes the gap is visibility of what is actually installed and inspection of where those apps send traffic, so an unofficial app communicating with a known malicious domain is caught after installation rather than never.

Related Resources

Related Resources

Read the latest news on endpoint threat detection and response from the experts.

Read the latest news on endpoint threat detection and response from the experts.

  • Multimodal AI Technology Concept with Digital Blocks Representing Artificial Intelligence Technologies
    blog

    Blog

    AI Governance: A Definitive Guide (2026)

    Read more
  • third party app risk
    blog

    Blog

    When WhatsApp Isn’t WhatsApp: Third party app store risk

    Read more
  • AI Apps
    blog

    Blog

    Shadow AI on Mobile: The Need for AI Governance

    Read more
  • Complex network of binary code highlighting data flow and cybersecurity concepts
    blog

    Blog

    We caught a banking app using a weak cipher suite. Here’s how.

    Read more