White Ops discovers a collection of Android apps that installed a hidden browser to load malicious ads. Google has removed an unknown number of Android apps from the official Google Play Store that appear to have been part of an ad fraud botnet.
This botnet called Terracotta was discovered by the Satori Security Team at White Ops, a security firm that specializes in detecting bots.
White Ops researchers said they have been tracking Terracotta since late 2019 when the botnet appears to have first been released.
According to researchers, Terracotta worked by uploading apps to the Google Play Store that promised users free products if they installed the apps on devices .
The apps typically offer free shoes, boots and sometimes tickets, vouchers and expensive dental treatments. Users were asked to install the app and then wait two weeks to receive the free items, during which they had to leave the app installed on their smartphone.

However, the apps downloaded and ran a modified version of WebView, a vulnerable version of Google Chrome. The Terracotta gang launched the modified WebView browser without the user's and carried out an ad fraud by loading ads and earning revenue from the fake ad impressions.
The White Ops team described Terracotta as a “complex and massive bot.” It was complex because it used advanced techniques to evade detection by fake ad networks , and it was massive because of the scale at which it operated.
For example, White Ops stated that in the last week of June alone, the Terracotta botnet “loaded” more than two billion ads onto 65,000 infected smartphones.
Some Terracotta apps have been removed from Google Play
Currently, following Google's intervention, the botnet's presence on the Play Store has been reduced, but not completely removed, with some devices appearing to be infected.
Some users may think that because the Terracotta malicious apps scammed ad networks and not users, this botnet may not be a problem for them, but, on infected devices, malicious apps often cause battery drain by running 24/7.
Unfortunately, White Ops has not released a list of apps infected with Terracotta. However, the good news is that when Google removes malicious apps from the Play Store, it also disables the malicious apps on all users' devices, stopping their malicious behavior.
