Google Removes 224 SlopAds Apps Behind Massive Global Ad Fraud

SlopAds: Massive Mobile Ad Fraud Scheme Exploits 224 Apps and 38 Million Downloads with Advanced Stealth Tactics

  • A large-scale ad fraud scheme called SlopAds involved 224 apps and gathered 38 million downloads worldwide.
  • The scheme used hidden app features and steganography to generate fake ad impressions and clicks.
  • At its peak, the operation saw 2.3 billion ad bid requests daily, with most activity from the U.S., India, and Brazil.
  • Google removed all identified apps from the Play Store following an investigation by HUMAN’s Satori Threat Intelligence and Research Team.
  • The attack triggered fraud only after certain types of downloads, making detection harder and adding to the complexity of mobile ad fraud threats.

A coordinated mobile ad fraud effort known as SlopAds operated across a network of 224 apps, reaching 38 million downloads in more than 220 countries and territories. The scheme, identified by HUMAN’s Satori Threat Intelligence and Research Team, aimed to create fake ad impressions and clicks to generate profit.

- Advertisement -

The team reported that these apps used advanced techniques such as steganography—hiding information inside image files—and concealed WebViews, which let the apps access threat actor-operated websites without user awareness. The fraudulent activity led to about 2.3 billion bid requests each day at its height. Most of the traffic originated from the United States (30%), India (10%), and Brazil (7%). Google responded by taking all related apps off the Play Store, stopping the scheme’s operations.

According to HUMAN, the deceptive behavior occurred only when the app was downloaded after clicking an ad. In these cases, the app reached out to a command-and-control server to download “FatModule,” a hidden code layer that enabled the fraud. If the app was installed organically, without following an ad link, it acted normally. “From developing and publishing apps that only commit fraud under certain circumstances to adding layer upon layer of obfuscation, SlopAds reinforces the notion that threats to the digital advertising ecosystem are only growing in sophistication,” HUMAN researchers said.

The “FatModule” component was hidden inside four PNG images, which the app decrypted and reassembled on the device. It collected device and browser information and executed ad fraud using hidden WebViews—a feature that allows web content to run inside an app. In this scheme, the fraudsters directed traffic to their own gaming and news websites, which displayed ads in invisible windows to collect revenue.

Researchers also noted that around 300 domains promoted SlopAds apps, often linking back to a main control server. The case follows a similar event earlier this year, when HUMAN discovered another ad fraud scheme involving 352 Android apps called IconAds. “SlopAds highlights the evolving sophistication of mobile ad fraud, including stealthy, conditional fraud execution and rapid scaling capabilities,” said Gavin Reid, CISO at HUMAN.

- Advertisement -

These developments emphasize increasing efforts by fraud actors to hide their activities and evade ad fraud detection methods.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

PYPL gains pre-earnings, Street split on AI commerce impact

Paypal's stock rose nearly 1% ahead of its quarterly earnings, potentially ending a seven-day...

OpenClaw Hype vs. Reality: AI Agent Rise Brings Serious Security Risks

The open-source AI agent framework OpenClaw amassed roughly 147,000 GitHub stars within weeks, sparking...

Bitcoin Tanks to $74.5K Amid $1.3B ETF Exodus

Bitcoin’s price fell to a year-to-date low of $74,555, marking a 40% drawdown from...

SpaceX Merges with xAI In $1.25 Trillion Vertical Integration Deal

SpaceX has officially acquired xAI, forming a single entity valued at $1.25 trillion.Elon Musk...

Hedera Developer Day Denver Feb 2026

The Hedera network will introduce a high-volume throttle system for entity creation (HIP-1313) alongside...
- Advertisement -

Must Read

10 BEST Companies to Buy Hosting With Bitcoin And Crypto

If you are looking to buy hosting with bitcoin or cryptocurrency then you've come to the right place.I've done the research for you...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!