A sophisticated Android ad fraud campaign called “SlopAds” has been shut down after researchers discovered 224 malicious applications on Google Play that were generating an staggering 2.3 billion fraudulent ad requests every day.
## Scale of the Operation
The campaign, uncovered by HUMAN’s Satori Threat Intelligence team, reached massive proportions:
– **38 million downloads** across 228 countries worldwide
– **2.3 billion daily bid requests** generating fraudulent revenue
– Primary targets: United States (30%), India (10%), and Brazil (7%)
The operation earned its “SlopAds” nickname due to the mass-produced nature of the apps, resembling AI-generated content, and the AI-themed applications found on the attackers’ command-and-control servers.
## How the Fraud Worked
The SlopAds campaign employed multiple sophisticated evasion techniques:
### **Dual Behavior System**
– Apps functioned normally when downloaded organically from Google Play
– Malicious behavior only activated when users arrived through the campaign’s advertisements
### **Advanced Concealment Methods**
1. **Firebase Remote Config**: Downloaded encrypted configuration files containing malware URLs
2. **Device Verification**: Checked if installation was on a legitimate user device rather than security analysis tools
3. **Steganography**: Hid malicious code within four PNG images that were later reassembled into the “FatModule” malware
### **Revenue Generation**
Once activated, the malware used hidden WebViews to:
– Collect device and browser information
– Navigate to fake gaming and news websites
– Generate continuous fraudulent ad impressions and clicks
– Create substantial revenue for the attackers
## Infrastructure and Response
The campaign’s infrastructure was extensive, featuring numerous command-and-control servers and over 300 promotional domains, indicating plans for significant expansion beyond the initial 224 identified apps.
**Google’s Response:**
– Removed all known SlopAds applications from Google Play Store
– Updated Google Play Protect to warn users about remaining installations
– Enhanced security measures to detect similar future campaigns
## Looking Forward
Security experts warn that the campaign’s sophistication suggests the threat actors will likely adapt their methods and attempt similar operations in the future. The incident highlights the ongoing challenge of detecting advanced mobile malware that uses legitimate app functionality as cover for fraudulent activities.
This case demonstrates the evolving nature of mobile security threats and the importance of continuous monitoring and advanced detection techniques to protect users from increasingly sophisticated fraud operations.
