Samsung has recently implemented additional security features in its devices, starting with One UI 6.1.1, to prevent sideloading apps from outside Google's Play Store or its own store without manual override. This move comes in response to a concerning report by Zimperium about a large-scale Android-targeted SMS stealer campaign that exploits sideloaded apps to steal crucial SMS 2FA codes and infiltrate corporate networks.
The report reveals alarming statistics, including 107,000 malware-laced apps, targeting of over 60 global brands for 2FA codes, attacks in 113 countries, operation of 13 command and control servers, and distribution through 2,600 Telegram bots. The vulnerability of sideloading apps has enabled this sophisticated malware campaign to evade detection by many antivirus solutions.