{"id":5108,"date":"2025-07-04T10:03:45","date_gmt":"2025-07-04T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/04\/massive-android-ad-fraud-iconads-leverages-google-play-to-attack-phone-users\/"},"modified":"2025-07-04T10:03:45","modified_gmt":"2025-07-04T10:03:45","slug":"massive-android-ad-fraud-iconads-leverages-google-play-to-attack-phone-users","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/04\/massive-android-ad-fraud-iconads-leverages-google-play-to-attack-phone-users\/","title":{"rendered":"Massive Android Ad Fraud \u2018IconAds\u2019 Leverages Google Play to Attack Phone Users"},"content":{"rendered":"<p>    Massive Android Ad Fraud \u2018IconAds\u2019 Leverages Google Play to Attack Phone Users<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated mobile ad fraud operation dubbed \u201cIconAds\u201d has infiltrated Android devices worldwide through 352 malicious applications distributed via Google Play Store, generating up to 1.2 billion fraudulent bid requests daily at its peak.<\/p>\n<p>The scheme represents a significant evolution in mobile advertising fraud, employing advanced <a href=\"https:\/\/cybersecuritynews.com\/malware-obfuscation\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscation<\/a> techniques to hide malicious apps from users while displaying intrusive out-of-context advertisements.<\/p>\n<p>The operation affected users globally, with the highest concentrations of fraudulent traffic originating from Brazil (16.35%), Mexico (14.33%), and the United States (9.5%).<\/p>\n<p>Unlike traditional adware, IconAds applications deliberately conceal their presence by replacing their visible icons with transparent rectangles and empty labels, making it nearly impossible for users to identify and remove the offending applications from their devices.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj1HVFoW-zW5JU7SG0tEGjS9gIQKY1GFelc3FvLlb-_ZFuycmCtuAJN_VpWeYSZGsKZunbbUW_r_XzKOpvhMnp5z7xZXh70B4wIlKSyA3-Jv2Qwl9r4q9968Pz8gf_cN-WbQq6jQsObt7L21ghaaslNOaKxmr1IMfxs8JNrmvhMDR0Jvt8W5H6SFblIWhw\/s16000\/Global%2520distribution%2520of%2520IconAds-associated%2520traffic%2520%28Source%2520-%2520Human%2520Security%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Global distribution of IconAds-associated traffic (Source \u2013 Human Security)<\/figcaption><\/figure>\n<\/div>\n<p>Human Security analysts <a href=\"https:\/\/www.humansecurity.com\/learn\/blog\/satori-threat-intelligence-alert-iconads\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the operation as an expansion of a threat they have been monitoring since 2023, noting significant tactical adaptations that emerged in October 2023.<\/p>\n<p>The researchers discovered that IconAds represents a new level of sophistication in mobile ad fraud, combining multiple layers of obfuscation with innovative <a href=\"https:\/\/cybersecuritynews.com\/abusing-dmsa-active-directory\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> mechanisms.<\/p>\n<p>The malware\u2019s most distinctive feature lies in its icon-hiding mechanism, which exploits Android\u2019s activity-alias functionality to replace legitimate app icons with invisible placeholders.<\/p>\n<p>This technique involves declaring a malicious activity-alias in the application manifest that overrides the default launcher activity after installation.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Persistence and Obfuscation Tactics<\/strong><\/h2>\n<p>The IconAds operation employs a sophisticated persistence mechanism centered around Android\u2019s <code>setComponentEnabledSetting<\/code> method, which allows applications to dynamically modify their visible components.<\/p>\n<p>Upon installation, the <a href=\"https:\/\/cybersecuritynews.com\/malicious-app-on-amazon-store\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious apps<\/a> initially display legitimate icons and names to avoid suspicion. However, once launched, they execute code that enables a hidden activity-alias while disabling the original launcher activity.<\/p>\n<p>The technical implementation involves creating an activity-alias with an empty android:label attribute and a transparent drawable resource.<\/p>\n<p>This approach ensures that even after device reboots, the malicious app remains hidden while continuing to display intrusive advertisements.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYjKr3jIPWTbakMC-cnYog5YtyFUzqZViZQ7vA4xS5sRPaYN-XHu6FIlOVVwVjuGWZFocf25uAsTEkmIXMNaTl4hQ7QRGOTI5XPpnJeQ45Er_S80SmlPqjDYctFrVKUjMSYmp6bf1vUBiUnxbpSwCoxn2_XImgw1TMZ2gbSCGL51m04M3888F7tPSkVZ4\/s16000\/Ads%2520loaded%2520out%2520of%2520context%2520%28Source%2520-%2520Human%2520Security%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Ads loaded out of context (Source \u2013 Human Security)<\/figcaption><\/figure>\n<\/div>\n<p>Some variants take the deception further by mimicking Google\u2019s own applications, using modified versions of the Play Store icon and \u201cGoogle Home\u201d branding to appear as legitimate system components.<\/p>\n<p>The operation\u2019s command-and-control infrastructure demonstrates remarkable sophistication, with each malicious app communicating through unique domains following a consistent pattern.<\/p>\n<p>These domains employ seemingly random English words to obfuscate device information during network communications, making detection and analysis significantly more challenging for security researchers.<\/p>\n<p>Google has since removed all identified IconAds applications from the Play Store, and users with <a href=\"https:\/\/cybersecuritynews.com\/malicious-apps-on-google-play\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Play Protect<\/a> enabled receive automatic protection against these threats.<\/p>\n<p>The discovery highlights the ongoing evolution of mobile ad fraud and the need for continued vigilance in app store security measures.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/massive-android-ad-fraud-iconads-leverages-google-play\/\">Massive Android Ad Fraud \u2018IconAds\u2019 Leverages Google Play to Attack Phone Users<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/massive-android-ad-fraud-iconads-leverages-google-play\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Massive Android Ad Fraud \u2018IconAds\u2019 Leverages Google Play to Attack Phone Users A sophisticated mobile ad fraud operation dubbed \u201cIconAds\u201d has infiltrated Android devices worldwide through 352 malicious applications distributed via Google Play Store, generating up to 1.2 billion fraudulent bid requests daily at its peak. The scheme represents a significant evolution in mobile advertising [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5108","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5108"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5108"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5108\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5108"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5108"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5108"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}