/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sophos researchers find 25 “fleeceware” apps on the Play Store, installed by 600M+ users, that abuse the apps' free trial mechanic to charge obscene fees

Catalin Cimpanu / ZDNet :

ZDNet Catalin Cimpanu

Context & Ripple Effects

Sophos' January 2020 disclosure marks the moment 'fleeceware' got a name: 25 Play Store apps with 600M+ installs that stay inside Google's rules while weaponizing the free-trial mechanic against users. It is the subscription-era successor to an older Play Store abuse pattern — the premium-SMS apps secretly charging users via text messages that researchers flagged back in 2017.

What makes this report matter is how it reframed app-store fraud from rule-breaking to rule-abuse: these apps pass review because they disclose their terms, just in ways designed to be missed. The pattern did not stay contained — Sophos went on to find the same trial-abuse playbook among top-grossing iOS apps within months (30+ fleeceware apps on the App Store), and the count kept climbing.

First-order effects

  • Google faces immediate takedown pressure on 25 specific apps reaching an install base of over 600 million, while users who signed up for 'free trials' are being billed recurring fees they did not meaningfully consent to.
  • Sophos converts its research into a named category — fleeceware — giving both stores and security buyers a label for a threat class that previously looked like ordinary apps.

Second-order effects

  • Apple's App Store gets pulled into the same scrutiny, since the trial mechanic is shared infrastructure — and indeed the same researchers surfaced the pattern there months later, including among highest-grossing apps.
  • App-store operators face pressure to redesign trial-to-subscription flows themselves, because review teams cannot catch abuse that is technically compliant — shifting the burden onto billing UX and refund policy rather than malware scanning.

Third-order effects

  • If the trajectory holds — from 25 apps here to the 204 fleeceware apps researchers catalogued across both stores a year later — subscription-trap design becomes a persistent gray-market industry living inside official storefronts, forcing platforms to police intent rather than code.
  • Consumer trust in free trials erodes structurally, pushing legitimate developers toward harder paywalls upfront and giving regulators a fresh angle on app-store billing practices.

The trend: Mobile app fraud is migrating from overt technical exploits like premium-SMS dialers toward legally compliant subscription traps that exploit store mechanics, scaling faster than platform review can catch.

Discussion

  • Vox Sara Morrison on x
    “Privacy shouldn't be a luxury”: Advocates want Google to do more to secure cheap Android phones
  • @sophoslabs @sophoslabs on x
    #Fleeceware charges excessive amounts of money for apps if users don't cancel a “subscription” before the short free trial window closes. The app below displays daily horoscopes for $69.99 a week, which adds up to an annual price of $3,639.48 More: https://news.sophos.com/... htt…