Massive fraud campaign: Google removes over 200 Android malware apps

Massive fraud campaign: Google removes over 200 Android malware apps


A massive Android app fraud operation has been exposed: Google has removed 224 apps from the Play Store that were part of a massive ad fraud operation, providing lucrative profits for those behind it.

Massive Fraud: Google Removes Over 200 Android Malware Apps

A massive Android app fraud operation has been exposed: Google has removed 224 apps from the Play Store that were part of a massive ad fraud operation, providing lucrative profits for those behind it.

Nadine Dressler
September 21, 2025, 11:30 AM
Google, Android, Hacker, Security, Malware, Trojan, Virus, Adware Portal gda / Flickr
Multi-layered Disguise
According to the HUMAN Satori Threat Intelligence Team, which discovered the attack, these apps have been downloaded over 38 million times in total, affecting 228 countries and regions worldwide.

The infected apps were initially inconspicuous. Users who installed them directly from the Play Store were able to use the advertised features normally. Only when installed through an ad campaign from a fraudulent network does a complex mechanism activate behind the scenes. These apps use Google's Firebase Remote Config to download encrypted configuration files, which include URLs pointing to the malicious code module and a so-called "cashout" server.

Over 300 domains are being used.

Extremely complex: Parts of the actual malicious code are hidden within PNG images. The attackers utilize steganography to conceal fragments of the malicious APK within image files, which are then assembled on the device. This "FatModule" utilizes a hidden WebView to collect device information and redirect users to fraudulent websites that continuously display ads and simulate clicks.

The underlying infrastructure is massive. In addition to the 224 exposed apps, the attackers also used over 300 domains impersonating news or gaming websites. This generates billions of fake ad impressions and clicks daily, generating continuous revenue.

Why is this a problem for end consumers?

The threat to data protection: These apps collect information about devices, users, and their online activities in the background—often without explicit consent and without visibility into the app's behavior. Performance Issues: Because WebViews hidden in the background continuously load deceptive ads, this can reduce battery life, strain internet connections, and impact device performance.
Malware Risk: Downloadable modules ("FatModules") that enter the system through steganography can open up further attack surfaces for malware and data exfiltration.
Ad fraud has a cascading effect: users indirectly waste ad budgets, ultimately raising prices for legitimate services and apps.

Google Responds—But the Danger Remains
Following the disclosure of this attack campaign, Google has removed all affected apps and updated Google Play Protect to proactively warn users not to install or use them.

Aceii One robot replaces tennis coach

Robotic applications are gradually expanding beyond factories into tennis. Aceii One is both a serving machine and a sophisticated coach powered by artificial

Aceii One robot replaces tennis coach

Samsung will upgrade its smartphone cameras with the release of One UI 8.5

Samsung is testing new camera features that may be released with One UI 8.5. According to firmware leaks from enthusiasts, the default video editor will now su

Samsung will upgrade its smartphone cameras with the release of One UI 8.5

‌2025 Flagship Chip Showdown: Qualcomm Snapdragon 8 Extreme Edition vs. Dimensity 9500 Full Comparison

Today, tech media outlet Android Headline released an in-depth comparison, revealing a head-to-head battle between the two core Android flagship chipsets of 20

‌2025 Flagship Chip Showdown: Qualcomm Snapdragon 8 Extreme Edition vs. Dimensity 9500 Full Comparison

OpenAI releases GPT-5-Codex model API: Revolutionary improvement in programming efficiency

OpenAI today officially launched an API for its latest AI model, GPT-5-Codex, which demonstrates groundbreaking capabilities in programming. The model maintain

OpenAI releases GPT-5-Codex model API: Revolutionary improvement in programming efficiency

MediaTek releases Dimensity 7360 processor: setting a new benchmark for the mid-range market with 200 million pixels and gaming optimization

MediaTek recently officially launched the Dimensity 7360 processor, targeting the mid-range market. With features such as an octa-core design, 200-megapixel su

MediaTek releases Dimensity 7360 processor: setting a new benchmark for the mid-range market with 200 million pixels and gaming optimization

NVIDIA Open Sources Audio2Face Model: Revolutionary Breakthrough in Game and Film Character Animation

NVIDIA recently announced the open source release of its generative AI facial animation model, Audio2Face. This technology analyzes acoustic features such as p

NVIDIA Open Sources Audio2Face Model: Revolutionary Breakthrough in Game and Film Character Animation

Intel Seeks Apple Investment: Semiconductor Foundry Cooperation May Become a New Focus

After securing investments from SoftBank, the US government, and Nvidia, Intel, led by Lip-Mou Tan, is accelerating its external partnerships. Bloomberg report

Intel Seeks Apple Investment: Semiconductor Foundry Cooperation May Become a New Focus

Qualcomm will hold the Snapdragon Summit today and is expected to release the Snapdragon 8 Elite Gen 5

According to official news, Qualcomm will hold the first day of its 2025 Snapdragon Summit on September 24th, focusing on the launch of its next-generation fla

Qualcomm will hold the Snapdragon Summit today and is expected to release the Snapdragon 8 Elite Gen 5

Huawei will release two new wearable products today: WATCH GT6 + FreeClip 2

According to official information, Huawei Device will hold a wearable and audio product launch event at 2:30 PM on September 24th, unveiling the new Huawei WAT

Huawei will release two new wearable products today: WATCH GT6 + FreeClip 2

The era of AI crime has arrived: Hackers use generative technology to launch cyberattacks

While many companies are still exploring the application scenarios of generative AI, criminal organizations have already thoroughly weaponized it. Recent secur

The era of AI crime has arrived: Hackers use generative technology to launch cyberattacks

iPhone 17 series first sales data exposed: Standard version reaches 185% of the previous generation

Apple's latest iPhone 17 series has officially launched its first sales, and its market performance has far exceeded expectations. Data from an e-commerce

iPhone 17 series first sales data exposed: Standard version reaches 185% of the previous generation

Huawei nova Flip S color and memory versions leaked: 6 colors + up to 1TB

Recently, detailed specifications for Huawei's new small foldable phone, the nova Flip S, have been leaked online. According to a digital blogger and infor

Huawei nova Flip S color and memory versions leaked: 6 colors + up to 1TB

Xiaomi Mi 17 Pro series debuts the Shadow Hunter 950L sensor, codenamed the King of Backlight

On September 24th, Xiaomi officially announced that its new flagship Xiaomi 17 Pro series, codenamed "King of Backlight," will be released at 7 PM on the 25th

Xiaomi Mi 17 Pro series debuts the Shadow Hunter 950L sensor, codenamed the King of Backlight

OPPO Watch S officially announced its global debut on October 16th! Focusing on the concept of lightness and thinness

On September 24th, OPPO announced on its official Weibo account that the OPPO Watch S smartwatch will debut globally on October 16th. According to official inf

OPPO Watch S officially announced its global debut on October 16th! Focusing on the concept of lightness and thinness

Qualcomm CEO: 6G pre-commercial equipment will be widely deployed as early as 2028

On September 24th, at the 2025 Snapdragon Summit, Qualcomm President and CEO Cristiano Amon stated that 6G pre-commercial equipment will be deployed on a large

Qualcomm CEO: 6G pre-commercial equipment will be widely deployed as early as 2028