Staff Reporters
Aug 8, 2023

Invisible ad fraud uncovered on Google Play apps, affects millions of Korean Android users says new cyber report

Researchers have uncovered 43 rogue apps that collectively received 2.5 million covert downloads, violating Google Play's developer standards.

Invisible ad fraud uncovered on Google Play apps, affects millions of Korean Android users says new cyber report
Cybersecurity experts McAfee's Mobile Research team has uncovered a concerning practise, whereby apps distributed through Google Play are covertly loading ads while the user’s device screen is turned off.
 
In an advisory released last Friday, the organisation revealed that whilst this may be a convenient way for developers to make money without subjecting consumers to invasive adverts, the action in fact, is a violation of Google Play's developer standards which specify how advertisements should be shown. 
 
"This affects not only the advertisers who pay for invisible ads, but also the users as it drains battery, consumes data and poses potential risks such as information leaks and disruption of user profiling caused by clicker behaviour," said McAfee.
 
The research uncovered 43 rogue apps that collectively received 2.5 million downloads, with the well-known TV/DMB player, music downloader, news, and calendar apps being amongst the most affected categories.
 
The apps in question used an advanced ad fraud library that deploys delay techniques to avoid detection and inspection. The fraudulent behaviour can also be remotely changed and pushed using the Firebase Storage or messaging services, which makes it more difficult to identify the malicious activity.
 
Once installed, the adware requests certain rights like "Power Saving Exclusion" and "Draw Over Other Apps," enabling covert background operations, according to McAfee. This lets in more malicious activity, such as showing phishing pages and ads without the user's knowledge.
 
When the device screen is off, the ad fraud starts retrieving and loading ads while the users are still unaware. In order to receive advertisement URLs from Firebase Storage, the library registers device information and requests particular domains, taxing the battery and using up mobile data.
 
McAfee have reported their findings to Google, resulting in a number of the apps being updated to conform with their regulations, and others deleted from the Play Store entirely.
 
McAfee has said it is essential for users to exercise caution and carefully evaluate the necessity of granting permissions such as the power saving exclusion before allowing them. While these might be required for certain legitimate functionalities for running in the background, it is important to consider the potential risks linked with them, such as enabling hidden behaviours or reducing the relevance of ads and contents displayed to users because of the hidden clicker behaviour.
 
Source:
Campaign Asia

Related Articles

Just Published

1 day ago

Creative Minds: How Yuhang Lin went from dreaming ...

The Shanghai-based designer talks turning London Tube etiquette into a football game, finding inspiration in the marketing marvels of The Dark Knight, and why he wants to dine with Elon Musk.

1 day ago

Happy holidays from team Campaign!

As the Campaign Asia-Pacific editorial team takes a holiday bulletin break until January 6th, we bid farewell to 2024 with a poetic roundup of the year's defining marketing moments—from rebrands that rocked to cultural waves that soared.

1 day ago

Year in review: Biggest brand fails of 2024

From Apple’s cultural misstep to Bumble’s billboard backlash and Jaguar’s controversial rebrand, here’s Campaign’s take on the brands that tripped up in 2024, offering lessons in creativity, cultural awareness, and the ever-tricky art of reading the room.

1 day ago

Former GroupM China executives to face Shanghai ...

EXCLUSIVE: The trio will appear before Shanghai's Intermediate Court next week, marking the latest chapter in the bribery scandal that rocked WPP's GroupM China in October last year.