How to secure the installation of an APKM or XAPK file?

  • Defence
  • Cyber
  • Cybersecurity

© Ercom-Illustrator

  • Type Insight
  • Published

The way Android applications are installed has changed dramatically, with new formats like APKM and XAPK adding both flexibility and complexity. While these formats make it easier to deploy advanced apps outside the Play Store, they also bring new security challenges for organisations. Read on to learn how you can secure your mobile deployments and stay in control.

Installing an Android application used to be straightforward: a single APK file was enough to deploy the app onto a device. However, the Android ecosystem has evolved significantly. Since 2021, the Android App Bundle file format has become mandatory for all new applications published on the Google Play Store. This format enables the deployment of larger applications in the form of a package that includes both code and resources.

While this evolution has made the manual installation of applications outside the store more complex, APKM and XAPK file formats now make it possible to bundle all the required elements into a single file for manual installation. But for CIOs and CISOs, one key question remains: what security risks are associated with using these files, and how can their installation be secured?

APK, XAPK, APKM: what are the differences between these formats?

APK (Android Package Kit) is Android’s original file format. It is a single, ready-to-install file containing the application itself, comparable to a Microsoft .exe file. However, this format is no longer suitable for most modern applications. Since the rise of Android App Bundles, a single file is often no longer sufficient to install a complete application outside the Google Play Store.

This is where so-called “container” formats come into play. One example is XAPK (eXtended Android Package Kit), which combines the APK file with additional resources, such as an OBB (Opaque Binary Blob) file containing supplementary data essential for the application to function properly. It is therefore a format designed for larger applications where a standard APK alone is insufficient.

APKM is another container format. Unlike XAPK, it is not intended to include large data files, but rather to package multiple APKs within a single archive. This format was introduced by the APKMirror platform. It combines a base APK with several configuration APKs to enable complete installation outside the Play Store across different types of devices.

What are the advantages and disadvantages of these formats?

For CIOs and CISOs, APKM and XAPK formats primarily offer operational benefits. They make it possible to install applications requiring multiple components in a single operation, whether that involves an APK with additional data or an application split into several modules.

By bundling everything required into one file, these formats significantly reduce the risk of incomplete installations during manual deployment outside the Google Play Store. In short, they simplify, speed up, and improve the reliability of Android application installation outside the official store.

However, these formats also present several drawbacks. First, Android does not always support them natively. Installation may therefore depend on a third-party application, adding another technical layer that must be managed. The most significant concern is security, as these files may come from unofficial or insufficiently controlled sources.

If employees resort to sideloading by installing applications from outside the Google Play Store, your organisation may be exposed to files containing malware or applications that do not comply with internal security policies. Installed versions may also be altered or no longer maintained by their publisher.

From a user experience perspective, teams may be less familiar with these formats than with standard APK files. As a result, installation may appear more technical for some users, particularly in the absence of a clearly defined IT process.

How can APKM and XAPK file installation be secured?

With the growing use of off-store installations and the increasing complexity of Android applications, the challenge no longer lies solely in the technical installation process. From a security perspective, it is essential to monitor application installations, know where files originate from, and control the conditions under which they are deployed. The use of formats such as APKM and XAPK therefore needs to be governed through a framework capable of centralising, verifying, and industrialising application deployment.

Our Cryptosmart Mobile solution has been designed precisely with this objective in mind. In addition to protecting your mobile communications, the Cryptosmart device includes an application catalogue. Application deployment is centralised through the MDM (Mobile Device Management) Push Manager, enabling your organisation to control sideloading and regain control over installations. This allows you to ensure the integrity, authenticity, and compliance of applications installed on employees’ devices.

The solution also helps you manage permissions and supervise updates two essential aspects when reducing the risks associated with installing unapproved applications and the proliferation of versions not validated by your IT department.

Finally, this approach enables a unified deployment model: applications in APK format can be installed for simple use cases (SNCF, Air France, etc.), while APKM or XAPK formats can be used for more modular applications (Google, Firefox, etc.).

APKM and XAPK formats address a major evolution in Android by simplifying the installation of applications outside the Play Store. However, they require strict governance to avoid the risks associated with sideloading and to maintain control over file origins and the integrity of installed versions. Cryptosmart Mobile is the benchmark solution for ensuring data encryption and securing mobile communications to a restricted distribution level*. Its MDM Push Manager provides a centralised and secure framework for deploying, updating, and controlling APK, APKM, and XAPK applications across your entire mobile fleet.

*Currently undergoing renewal.

  • Defence

Frugal AI: the key to embedding artificial intelligence in combat optronics

Insight
  • Research & innovation

Thales and ELI-NP Renew their partnership with a new maintenance support contract for the World-Class 10-Petawatt Laser System

Insight
  • Cybersecurity

Thales researchers explain why the defence against the quantum threat starts now

Insight
  • Cybersecurity

Game On: How Bot Attacks Are Threatening the Digital Fan Experience

Insight
  • Research & innovation

From Mars to nuclear fusion, Thales stretches the frontiers of high-power laser technology

Insight
  • Defence

How to stop the use of unsecured attachments without hampering your teams’ productivity

Insight
  • France

Thales and DCI join forces to revolutionise operational command

News in Brief
  • Air defence

On Thales’ missile optronics and electronics repair lines, augmented maintenance is becoming a reality

Insight
  • Europe

Thales launches OT XDR capability to improve visibility across IT and OT environments

News in Brief