home

Mobile Endpoint Security

Lookout Product Documentation

Find answers about using and optimizing Lookout products.

APPLICATION/FILE Threat Classifications

Classification Description
ADWARE
Automatically displays ads.
APP_DROPPER
Downloads and/or installs additional apps on a device.
BACKDOOR
Allows a third party to access or control a device.
BLACKLISTED_APP

Blacklisted apps are defined by MES Console administrators.

The MES console and Mobile Risk API v2 refer to this classification as DENYLISTED_APP.

BOT
Automatically performs specific operations.
CHARGEWARE
Sends premium messages or executes other actions that charge the user.
CLICK_FRAUD
Executes actions without user permission, such as subscribing to paid services.
CONNECTIVITY
The app uses Bluetooth or Near Field Communication (NFC) in a manner that leaves the device vulnerable.
DATA_LEAK
The app may not be malicious, but it transmits data in an unsecured manner.
EXPLOIT
The app uses OS flaws to gain elevated privileges.
NON_APP_STORE_SIGNER
A non-App Store signer indicates that an app has been installed from a source other than the iOS App Store.
RISKWARE
The author of the app has signed malicious or potentially unwanted applications in the past.
ROOT_ENABLER
Lets a user acquire and manage root access.
SIDELOADED_APP
Sideloaded apps are apps installed from a source other than an official app store.
SPAM
Uses the device to send spam via calls or SMS.
SPY
Sends user and device information to a third party.
SURVEILLANCE
Monitors device activity and sends information to a third party.
TOLL_FRAUD
Fraudulently charge users.
TROJAN
Claims to be something else, but is malicious and can cause data theft or loss of control over a device.
VIRUS
Runs and replicates itself after a user accesses a compromised file or program.
VULNERABILITY
The app itself may not be malicious, but it exposes the device to potential threats by having known vulnerabilities.
WORM
A virus that can replicate and spread without the use of a host file.