A sophisticated ad fraud scheme called “SlopAds” has been dismantled after operating a network of 224 malicious apps that collectively garnered 38 million downloads across 228 countries. The operation represents one of the most advanced mobile advertising fraud campaigns discovered to date.
## How the Fraud Worked
The SlopAds operation employed cutting-edge deception techniques to avoid detection while maximizing fraudulent revenue. The malicious apps used steganography—a method of hiding data within images—to conceal their fraud capabilities and created invisible web browsers to generate fake ad clicks and impressions.
What made this scheme particularly clever was its conditional activation system. When users downloaded these apps, the software would check whether the download came directly from the Google Play Store or through an advertisement. If the app detected it was downloaded after clicking an ad, it would activate its fraud module called “FatModule.” However, if downloaded organically, the app would function normally as advertised—making detection extremely difficult.
## Scale and Impact
At its peak, the SlopAds network generated an staggering 2.3 billion fraudulent bid requests daily. The majority of traffic originated from:
– United States (30%)
– India (10%)
– Brazil (7%)
The operation’s name references both the mass-produced nature of the apps and the threat actors’ use of AI-themed services like StableDiffusion and ChatGLM hosted on their command servers.
## Technical Sophistication
The fraud payload was delivered through four PNG image files that concealed the malicious code. Once decrypted and assembled, this “FatModule” would:
– Collect device and browser information
– Create hidden web browsers
– Navigate to attacker-controlled websites
– Generate fraudulent ad impressions and clicks
The criminals monetized their scheme through HTML5 gaming and news websites they controlled, which displayed frequent advertisements in hidden browsers, generating revenue from fake interactions.
## Detection and Response
HUMAN’s Satori Threat Intelligence team discovered the operation and reported their findings. Google has since removed all identified malicious apps from the Play Store, effectively shutting down the threat. Researchers identified approximately 300 domains connected to promoting these fraudulent applications.
## Growing Threat Landscape
This discovery follows another major mobile ad fraud scheme called “IconAds,” which involved 352 Android apps just two months earlier. According to HUMAN’s CISO Gavin Reid, “SlopAds highlights the evolving sophistication of mobile ad fraud, including stealthy, conditional fraud execution and rapid scaling capabilities.”
The incident underscores the increasing complexity of digital advertising threats and the ongoing cat-and-mouse game between cybercriminals and security researchers in the mobile ecosystem.
