Alert: Massive Ad Fraud Scheme Targets 60M+ Users Through 331 Infected Apps


# Massive Ad Fraud Campaign Targets Android Users Through Malicious Apps

Cybersecurity experts have uncovered a widespread ad fraud operation that utilized hundreds of malicious applications on the Google Play Store to bombard users with intrusive ads and conduct phishing attacks.

Dubbed “Vapor,” the campaign was initially identified by Integral Ad Science (IAS) and further investigated by Bitdefender, who discovered that the scope was even larger than first reported. The operation involved at least 331 fraudulent apps that collectively amassed over 60 million downloads.

## Sophisticated Deception Tactics

The threat actors employed several sophisticated techniques to evade detection:

– Creating multiple developer accounts with only a few apps each to minimize impact if discovered
– Using “versioning” to initially publish clean apps that pass Google’s security checks before adding malicious features in updates
– Hiding app icons from the device launcher after installation
– Leveraging Leanback Launcher (designed for Android TV) to operate stealthily
– Impersonating legitimate services like Google Voice

## Harmful Activities

Once installed, these malicious apps:

– Display full-screen, intrusive advertisements that render devices nearly unusable
– Attempt to collect credit card information and login credentials through phishing attacks
– Exfiltrate device information to attacker-controlled servers
– Start without user interaction, bypassing Android 13 security restrictions

The campaign appears to have begun around April 2024 before significantly expanding in early 2025, with over 140 fraudulent apps uploaded in October and November alone.

Google has since removed the identified applications from the Play Store, though researchers believe the operation may be the work of either a single threat actor or multiple cybercriminals using the same malware packing tool available on underground forums.

Share This Article