An app claiming to help you visualize your dream kitchen in augmented reality climbed to the very top of the US iPhone App Store — before anyone noticed it wasn’t a kitchen app at all. K8CHEN PRO was, in reality, a client app for T-Bank, one of the Russian financial institutions currently under US sanctions.
This wasn’t a one-off. Back in June, three separate US-sanctioned Russian banks were caught quietly slipping client apps onto the App Store. K8CHEN PRO is simply the latest — and arguably the boldest — entry in a growing pattern of banking software hiding behind an innocent-looking front.
The disguise, to its credit, was thematically committed: an AR-powered kitchen modeling tool, complete with an App Store listing to match. But it didn’t hold up long. Open the app and the facade collapses almost immediately, revealing the actual banking functionality underneath. Even the paperwork gave the game away — the app’s privacy policy, linked directly from its App Store page, was flagged as being churned out by a “Free Privacy Policy Generator.” Not exactly the hallmark of a legitimate financial product operating in the US market.
The more interesting question isn’t how the app worked, but how it kept getting through in the first place. Apple’s review process is famously strict — developers routinely complain about rejections over far more trivial issues — yet these repurposed banking apps have now slipped past screening multiple times. There’s a certain irony at play here, too: the very thing that got K8CHEN PRO noticed was its success. The higher an app climbs the charts, the more eyes land on it, and the more obvious it becomes that it doesn’t belong in the store.
That’s exactly how this one ended. Once the app gained enough visibility to top the iPhone chart, its true nature became impossible to ignore, and Apple pulled it from the App Store — the same fate that met the earlier June cases once they were publicized.
The episode highlights an awkward gap in App Store moderation. Automated and human review can catch overt policy violations, but a well-themed disguise — a plausible category, matching screenshots, a generic privacy policy — appears to be enough to sail through initial approval. Enforcement, in these cases, has effectively been crowdsourced: the apps don’t get caught during review, they get caught after they go viral.
For everyday users, the practical takeaway is a familiar one. A top-charting app with a slick listing isn’t automatically what it claims to be. When even a supposed AR kitchen designer can turn out to be a sanctioned bank in disguise, a quick glance at the developer, the reviews and — yes — the privacy policy is time well spent.