HomeSecurityAd fraud: Google removes 224 apps from the Play Store

Ad fraud: Google removes 224 apps from the Play Store

A widespread ad fraud operation, dubbed “SlopAds” , was recently disrupted after 224 malicious apps on Google Play were leveraged to generate a massive volume of fake ad requests — up to 2.3 billion ad requests per day. The campaign was discovered by HUMAN ’s Satori Threat Intelligence , which records that the apps had a combined total of more than 38 million installs before being taken down.

Google Ad Fraud

What was SlopAds and why is it causing alarm?

The researchers named the operation “SlopAds” because it involved mass-produced, low-quality — an “AI-slop” style — and because a collection of AI-themed apps and services as being hosted on the threat actors’ C2 server. The campaign was global: downloads came from 228 countries , with the highest concentration of fraudulent impressions coming from the US (≈30%), India (≈10%), and Brazil (≈7%).

See also: Signal: New APT28 attack distributes BeardShell and Covenant

How it worked — multiple layers of concealment

The most concerning aspect of the SlopAds campaign was its level of technical sophistication and its multi-layered obfuscation mechanism. When an app was installed “organically” from the Play Store without being prompted by a targeted ad, it behaved normally — performing the advertised functionality so as not to raise suspicion. However, if the user had reached the installation via one of the advertising links campaign’s, then the software used Firebase Remote Config to download an encrypted configuration file containing URLs for the ad fraud malware module, cashout servers, and a JavaScript payload.

Additionally, the creators used steganography as a means of transport: the malicious APK was “split” into a quad PNG images, which contained fragments of the code hidden within the pixels. The images were downloaded, decrypted, and the pieces were joined on the device to form the complete malicious module, called “FatModule”. This module then secretly executed WebViews, collected device/browser data, and directed the user to ad fraud (cashout) domains, controlled by the attackers. These domains mimicked games or new websites to display ads and “generate” fake impressions and clicks.

See also: New FileFix variant distributes StealC malware

Ad fraud: Google removes 224 apps from the Play Store

Impacts — who loses and how big the price is

The immediate profit goes to the attackers, who earn revenue from fraudulent ads and clicks. Hidden WebViews that continuously display ads can generate a huge number of impressions at very little cost to the malicious actors, but with implications for the integrity of the ad chain: advertisers pay for exposures that did not reach human eyes, DSP/SSP platforms and ad exchanges see distorted metrics, and ad ecosystems are undermined. The scale of 2.3 billion requests/day indicates that this was not a “local phenomenon” but an organized enterprise on an industrial scale.

What did Google/Play Protect do and what is the risk for the future?

Following the disclosure, Google removed the known SlopAds apps from the Play Store and updated Play Protect to notify users to uninstall them. However, HUMAN analysts warn that the complexity and modular setup of the campaign shows that the perpetrators are able and willing to adapt their tactics and resurface — either with new apps or different interception and camouflage techniques

See also: Hackers abuse MCP servers to collect sensitive data

Ad fraud: Google removes 224 apps from the Play Store

What users and advertising platforms can do

  • Users: check installed apps, uninstall suspicious apps you don't use, keep Android and apps up to date , and prefer trusted sources of information about apps.
  • Advertisers/media buyers: improve detection of anomalous traffic, check behavioral signals (e.g. excessively high number of impressions without corresponding engagement) and demand transparency from advertising platforms in distribution chains.
  • Platforms: strengthen the app review process with multi-layered analysis (static + dynamic + behavioral), monitoring for steganographic patterns, and stricter policies for apps driven by advertising campaigns.

SlopAds is a reminder that the mobile ad ecosystem continues to be a target for organized crime networks that combine techniques “born” from the web (Firebase, WebView) with rarer methods (image steganography). The response must also be technically advanced: partnerships between security companies, ad platforms, and the Android ecosystem itself are essential. HUMAN and other researchers predict that perpetrators will adapt — so vigilance and rapid information sharing remain critical.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS