Hi folks,
I'm working for a French cultural institution (the Centre des monuments nationaux) and we develop different apps that are used for bringing contents when visiting monuments. We usually have a small amounts of download per day / app (about 10-15) and since mid-August, we have a huge increase, as you are all experiencing, of download coming from China (400-500 per day/app) with 7 of our 12 apps and absolutely no activity whatsoever coming from theses downloads. Besides the analytics problem (it renders all download numbers fake, so we have to ignore the chinese downloads) it seems to have no other impact.
I have been investigating the subject during the last month, since chinese downloads have been going on with no interruption since August 15th. So far here is the extent of what I know / read / observe :
- This is a worldwide phenomenon, it doesn't seem to be limited to specific countries or activities
- Almost all of our chinese downloads (99,99%), according to iTunes Connect Analytics, have been done with iOS 10.2, which is rather strange > @all : do you make the same observation ? Maybe a vulnerability has been found in this iOS version that is used through the downloads of apps?
- When I have asked Apple about it, their first answer was "it might be coming from the volume purchase program" (same as one other developper from this page). However when I have sent them our stats and reports, showing it was not related, their answer changed to "we are investigating and will let you know" (since September 7th). I'm thinking they are trying to understand the problem too.
- The idea of having this phenomenon linked with the keywords in order to increase the ranking of others apps is interesting, but considering the extent of the phenomenon, it would be quite strange, no? Just so that you know, for our 7 apps our main keywords are (in french, related to cultural heritage) : monuments, CMN, Abbaye, famille, château, centre des monuments nationaux, Jardin, Château, Menhir, application, production, mobile. Anyone finds a pattern?
I am wondering, considering the fact that the downloads come mainly from iOS 10.2, that a vulnerability has been found in that version of iOS, and that someone uses it to cover another connexion behind (VPN access or else?). It is far etched though but I don't really have any other theory. It's not related to competition (can't say we really have any in our field).
Any other guess anyone?
Best,
David