Malloc: the fight vs conventional antivirus

Nov 28, 2022 | Company News
Author image

Maria Terzi

Co-Founder & CEO at Malloc

TL;DR: November was a super challenging month for Malloc. The five most important antivirus companies identified the Malloc Android app as spyware; the exact opposite of what the app really is. A misjudgement, based on false indicators. The conventional antivirus companies have now whitelisted the app, but the concerns they raised significantly affected our users’ trust. What happened, how we handled this situation, and how this helped us gain more than 20K new users, is all provided in this post.

Malloc against conventional antivirus

Imagine waking up one day, and receiving emails from your users and reviews on the Google Play store, accusing your app of being stalkerware, a trojan, spyware and all sorts of malicious technologies that exist. Well, this happened to Malloc, and you can only imagine our frustration. Some users shared their concerns by emailing us, others published bad reviews, and a lot of the users (mostly new) uninstalled the app.

Malloc was created with one single goal — to help people regain their privacy. We created Malloc to give control to users over what is happening on their devices, to enable them to see who collects their data and give them the power to stop it.

The Malloc app detects spyware and allows users to check where their data is being sent and block data collected by ads and spyware, by passing users’ traffic through secure VPN servers. Malloc keeps no logs by design and data lives only on the user’s device.

You can imagine how we felt when we, Malloc, were accused of being spyware. It is a horrible, horrible feeling. If you ever find yourself in this unfortunate position or when you have all your competitors against you, here are the steps we have taken to overcome this, and you may find useful:

  • Reassure users and mobilise them. Keep communicating with users, talk openly regarding the issue and your progress to resolve it. Mobilise users, ask users to contact and urge the companies to whitelist the app.
  • Address the issue the fast way. Contact the companies, explain to them that your app is not spyware and provide evidence to support your claims.
  • Understand, and solve the issue so it never happens again. Understand what triggered the false alarm in the first place and solve it.

It took us almost 2 weeks to get whitelisted by all antivirus companies that had been tagging Malloc. We had to identify all the companies, contact them and provide them with evidence for their false accusations. After multiple back and forth emails, one of the companies reached out explaining that what triggered the false alarm was a simple list of spyware domains that we had in the app in order to check on the device for specific apps.

So, let me explain. Malloc detects the presence of spyware such as Pegasus or Predator based on indicators. Those indicators have been compiled by Amnesty International after analyzing thousands of affected phones. The indicators include files created, processes running on the device, and domains that this spyware communicates with and sends data to. To enable faster, offline detection of spyware, we kept a list of those indicators in the Malloc app — a list that names the spyware and the indicators that we check for. When antivirus software scanned the app and detected the list, it automatically assumed that the app is spyware, just because there was a file with the spyware indicators. Not only did they assume that it was spyware, but they also charged us with all the illegal activities of the spyware, which was clearly a false statement. The antivirus claimed that the app uses permissions to access the camera and microphone and record users’ actions, when clearly it does not ask for such permissions.

Having the names of spyware in your app triggered the reaction of the antivirus, even if we used it to detect and block spyware — we have since encoded all references to spyware, to avoid such misjudgements.

It was an incredibly challenging month for Malloc, and you can imagine how discussing with your competitors about their mistreatment feels. The good news is, the misunderstanding is now resolved and Malloc triggers no alarms.

More importantly our users started fighting back! Public posts and complaints to traditional antivirus companies that were fighting us not only did not damage us, but helped Malloc grow its user base by more than 20K additional users. Malloc users took the situation into their hands and this is impressive.

Malloc will continue its fight against spyware and we are fully focused on helping users to detect spyware, block ads and data trackers, and protect their data.

For anyone who needs to get an app whitelisted, here are the contacts and links below.

Whitelisting links / contact emails

  • Avast: https://support.avast.com/en-ww/article/160?option=ftpwhitelisting#mac
  • AVG: https://support.avg.com/SupportArticleView?l=en&urlName=AVG-FTP-file-upload&supportType=home
  • ESET: whitelist@eset.sk
  • LookOut: support@lookout.com

Find out why Malloc is regarded as one of the best mobile security apps.

Relevant tags:

#Company News#Antivirus#Spyware#Trust#Malloc

Published on Medium

Related articles