Loading cryptocurrency prices...

Google Removes 224 SlopAds Apps Behind Massive Global Ad Fraud

SlopAds: Massive Mobile Ad Fraud Scheme Exploits 224 Apps and 38 Million Downloads with Advanced Stealth Tactics

  • A large-scale ad fraud scheme called SlopAds involved 224 apps and gathered 38 million downloads worldwide.
  • The scheme used hidden app features and steganography to generate fake ad impressions and clicks.
  • At its peak, the operation saw 2.3 billion ad bid requests daily, with most activity from the U.S., India, and Brazil.
  • Google removed all identified apps from the Play Store following an investigation by HUMAN’s Satori Threat Intelligence and Research Team.
  • The attack triggered fraud only after certain types of downloads, making detection harder and adding to the complexity of mobile ad fraud threats.

A coordinated mobile ad fraud effort known as SlopAds operated across a network of 224 apps, reaching 38 million downloads in more than 220 countries and territories. The scheme, identified by HUMAN’s Satori Threat Intelligence and Research Team, aimed to create fake ad impressions and clicks to generate profit.

- Advertisement -

The team reported that these apps used advanced techniques such as steganography—hiding information inside image files—and concealed WebViews, which let the apps access threat actor-operated websites without user awareness. The fraudulent activity led to about 2.3 billion bid requests each day at its height. Most of the traffic originated from the United States (30%), India (10%), and Brazil (7%). Google responded by taking all related apps off the Play Store, stopping the scheme’s operations.

According to HUMAN, the deceptive behavior occurred only when the app was downloaded after clicking an ad. In these cases, the app reached out to a command-and-control server to download “FatModule,” a hidden code layer that enabled the fraud. If the app was installed organically, without following an ad link, it acted normally. “From developing and publishing apps that only commit fraud under certain circumstances to adding layer upon layer of obfuscation, SlopAds reinforces the notion that threats to the digital advertising ecosystem are only growing in sophistication,” HUMAN researchers said.

The “FatModule” component was hidden inside four PNG images, which the app decrypted and reassembled on the device. It collected device and browser information and executed ad fraud using hidden WebViews—a feature that allows web content to run inside an app. In this scheme, the fraudsters directed traffic to their own gaming and news websites, which displayed ads in invisible windows to collect revenue.

Researchers also noted that around 300 domains promoted SlopAds apps, often linking back to a main control server. The case follows a similar event earlier this year, when HUMAN discovered another ad fraud scheme involving 352 Android apps called IconAds. “SlopAds highlights the evolving sophistication of mobile ad fraud, including stealthy, conditional fraud execution and rapid scaling capabilities,” said Gavin Reid, CISO at HUMAN.

- Advertisement -

These developments emphasize increasing efforts by fraud actors to hide their activities and evade ad fraud detection methods.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin Slips to $121K as Jobless Claims, Fed Uncertainty Weigh on Crypto

Major cryptocurrencies saw declines as investors reacted to new U.S. jobless claims data and...

Crypto Salaries Shrink in 2024 Despite Bitcoin Boom, Report Finds

Crypto industry salaries and token incentives dropped worldwide for most positions, based on new...

Solana TVL Hits All-Time High at $42.4B Despite Price Slump

The total value locked (TVL) on the Solana network has reached an all-time high...

Ethereum Leads Crypto Losses as Dollar Gains, Market Sees $530M Wipeout

Ethereum led cryptocurrency declines, falling up to 3.2% over 24 hours.Major cryptocurrencies, including Bitcoin...

Phala to Migrate from Polkadot to Ethereum Layer 2 After Vote

Phala community approved the migration from Polkadot to become an Ethereum Layer 2.Migration begins...
- Advertisement -

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...