Android Ad Scam Hijacks Phones; Drains Data, Battery
22 Android apps are eating up data allowances to benefit scammers at the expense of phone owners, a security firm says. The apps are using smart phones to carry out fraud against online advertisers.
Sophos says it's found 22 offending apps with a total of two million downloads. They are each described as offering simple games or basic utilities such as keeping the phone's flash activated to act as a flashlight. While they work as described, which helps get good online reviews and build credibility, the scam is happening behind the scenes. (Source: sophos.com)
The apps are used for click fraud, designed to scam advertisers. They work by retrieving, displaying and 'tapping' ads on pages created which were previously set up by scammers. The phone user never sees this happen as the pages are displayed in a hidden window that lies underneath whatever's visible on the phone screen.
Advertisers Pay For Bogus Views
Although there's no human being actually seeing the ad, it still racks up the number of clicks and views recorded by the scammer's website. They then get paid a per-view or per-click fee from the advertisers. Usually this works through a third-party ad network such as Google, putting an extra layer of distance between the scammers and the advertisers.
While the phone user isn't financially involved, they still suffer from two negative consequences. One is that the behind-the-scenes process eats up battery life, albeit in a way that's hard to isolate. The other is that the process of retrieving the ads uses up data (providing the user isn't connected to WiFi), which then eats into monthly data allowances. (Source: birminghammail.co.uk)
The apps were configured so that the click fraud was running almost constantly, even when the app itself was closed.
Android Handsets Disguised As iPhones
Rather cheekily, the click fraud sometimes disguised the details of the affected Android handsets and made it look like the ad views and clicks were coming from iPhones. Some advertisers pay more for traffic from Apple users as they believe they have bigger spending power.
Google has now removed the apps in question from the Play Store. Sophos recommends Android users check their phones and remove any of the following they find:
- AK Blackjack - com.maragona.akblackjack
- Animal Match - com.beacon.animalmatch
- Box Stack - com.mobile.boxstack
- Cliff Diver - com.mobile.cliffdiver
- Color Tiles - com.maragona.colortiles
- HexaBlocks - com.atry.hexablocks
- HexaFall - com.atry.hexafall
- Jelly Slice - net.kanmobi.jellyslice
- Join Up - com.pesrepi.joinup
- Just Flashlight - app.mobile.justflashlight
- Magnifeye - com.magnifeye.android
- Math Solver - com.mobilebt.mathsolver
- Neon Pong - com.pesrepi.neonpong
- PairZap - com.atry.pairzap
- Roulette Mania - com.beacon.roulettemania
- ShapeSorter - com.mobilebt.shapesorter
- Snake Attack - com.mobilebt.snakefight
- Space Rocket - com.pesrepi.spacerocket
- Sparkle FlashLight - com.sparkle.flashlight
- Table Soccer - com.mobile.tablesoccer
- Tak A Trip - com.takatrip.android
- Zombie Killer - com.pesrepi.zombiekiller
What's Your Opinion?
What measures do you take to reduce the risk of installing malicious apps? Does Google do enough to check what apps are actually doing? Have you ever noticed unexpectedly high battery or data use on your handset?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
Firewall would prevent this (mostly)
I use a free data and wifi firewall called NetGuard, which blocks all apps from using my data allowance (I'm using a pay-as-you-go data plan). I only allow a small number of apps to use my data - the rest are blocked by default. This would have prevented any data overages. NetGuard can also be configured to deny wifi and data for all new apps (by default), though most folks most likely wouldn't want to that.
It's too bad Google doesn't do more to detect this sort of thing from happening in the first place, though I imagine it would be difficult especially if data is going in and out through an encrypted connection such as a VPN.
Which pay-as-you-go data plan do you use?
Hi,
Which pay-as-you-go data plan do you use?
Which pay-as-you-go data plan is the best?
Thanks
Buzz
In Canada
I am in Canada and use Koodoo Mobile pay as you go - the cost is $15 a month for unlimited texting (which is all I need). Any top up (500 minutes of voice, data, etc) gets moved onto the next month if I don't use it so I am not continuously paying for voice and data. This is perfect for me since I am always near WiFi and can use that instead of data or voice.