"They click on a link, click the install button, and install the malware," he said.
The apps are also distributed through unofficial app stores, often hidden inside another application.
"Apps on the unofficial stores have huge abilities, to root the device, to escalate privileges," he said. "You try to root your device, but at the same time you are installing a malicious program and later it will download the banking Trojans."
Sign up for Computerworld eNewsletters.