FINDING · EVALUATION
Five participants confirmed installing GFW evasion tools exposed them to malware; prior work cited in the paper found >38% of Android apps using the VPN permission contain malware. Participants additionally reported fake gaming platforms that install adware and credential-stealing phishing pages; notably, VirusTotal did not flag any of the fake platform URLs identified by participants, indicating conventional AV tools provide insufficient protection.
From 2023-feng-study — A Study of China's Censorship and Its Evasion Through the Lens of Online Gaming · §8.4 · 2023 · USENIX Security Symposium
Implications
- Legitimate circumvention tools must publish cryptographically signed binaries with reproducible builds and maintain a single canonical download URL to differentiate themselves from the malware-laden fake-VPN ecosystem users are trained to distrust.
- Consider an in-app trust signal (e.g., prominent open-source repository link, transparency report) targeting technically sophisticated users who have been burned by credential-stealing fakes.
Tags
Extracted by claude-sonnet-4-6 — review before relying.