Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Ranch at Rock Creek’s brilliant 5-star business strategy

    December 4, 2025

    Your favorite AI tool just barely missed this security review – why that’s a problem

    December 4, 2025

    I saw drone delivery launch in Atlanta – how they work and which cities are next

    December 4, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Google Nukes 224 Android Malware app behind large -scale advertising fraud campaign
    Security

    Google Nukes 224 Android Malware app behind large -scale advertising fraud campaign

    PineapplesUpdateBy PineapplesUpdateSeptember 17, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Google Nukes 224 Android Malware app behind large -scale advertising fraud campaign
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google Nukes 224 Android Malware app behind large -scale advertising fraud campaign

    A large -scale Android advertisement fraud operation was dubbed after 224 malicious applications on Google Play was used to generate 2.3 billion advertising requests per day.

    Advertisement was discovered by fraud campaign Intelligence teamWhich stated that the apps were downloaded more than 38 million times and obfuscation and steganography were employed to hide malicious behavior from Google and safety equipment.

    The campaign was worldwide, in which users were installing apps from 228 countries, and slopad traffic accounting for 2.3 billion bidding requests every day. The highest concentration of Ad impression originated from the United States (30%), followed by India (10%) and Brazil (7%).

    “Researchers dubbed this operation ‘slopads’ because the appreaps associated with the danger have a large scale produced, a la’AI SlopeAs a reference to a collection of applications and services with A-themes, the danger was hosted on the C2 server of the actors, “Manav explained.

    Android apps associated with Slopads Advertising Fraud Campaign
    Android apps associated with Slopads Advertising Fraud Campaign
    Source: Human Satori

    Slopads advertising fraud campaign

    Advertisement In advertising fraud, Google’s app review process and safety software had several levels stolen strategies to avoid detection.

    If a user has systematically installed a slopad app through the Play Store, without one of the advertisements of the campaign, it will serve as a common app, which will normally demonstrate advertised functionality.

    Slopad advertisement fraud malware workflow
    Slopad advertisement fraud malware workflow
    Source: Human Satori

    However, if it was determined that the app was established by the user who was reached through one of the actor’s advertising operations, the software used the firebase remote configuration to download an encrypted configuration file which included the URL for advertising malware modules, cashout servers and a JavaScrip.

    The app will determine whether it was installed on a valid user’s device, rather than analyzed by a researcher or safety software.

    If the app passes in check, it downloads four PNG images that use stagnography to hide a malicious APK pieces, which are used to strengthen the advertising fraud campaign.

    Stepgi -vicious code hidden in images
    Stepgi -vicious code hidden in images
    Source: Human Satori

    Once downloaded, images were dec

    Once the fatmodule becomes active, it will use hidden webwules to collect the device and browser information and then navigate on the cachet (cashout) domain controlled by the attackers.

    These domains implemented games and new sites, which serve continuously advertisements through hidden webwine, to generate more than 2 billion fraud advertising impressions and clicks, which generates revenue for the attackers.

    Human says that the infrastructure of the campaign included several command-end-control servers and more than 300 related promotional domains, suggesting that the danger actors were planning to move beyond the initial 224 recognized apps.

    Google has since removed all known slopad apps from the Play Store, and Android’s Google Play Protect has been updated to warn users to uninstall any devices that are found on the devices.

    However, the human warns that the refinement of the advertising fraud campaign indicates that the actor of danger will customize his plan to re -try in future attacks.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    advertising Android app Campaign fraud Google large Malware Nukes scale
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article5 steps to deploy agent AI Red Teaming
    Next Article iPhone 17 Pro vs iPhone 14 Pro: Why am I upgrade to my model after three years of use
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    I compared the two best Android flagship phones of 2025 – and it was pretty close

    December 4, 2025
    Startups

    Here’s how much Apple, Meta, Google and more employees make

    December 2, 2025
    Startups

    Finally, an Android tablet that I wouldn’t mind keeping my iPad Pro for (especially at this price)

    November 30, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    The Ranch at Rock Creek’s brilliant 5-star business strategy

    December 4, 2025

    Your favorite AI tool just barely missed this security review – why that’s a problem

    December 4, 2025

    I saw drone delivery launch in Atlanta – how they work and which cities are next

    December 4, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.