logo

Invisible Adware: Unveiling Ad Fraud Targeting Android Users

ID: 470faabe-63c0-5f9c-b367-2c28b86762ea

STIX ID: report--470faabe-63c0-5f9c-b367-2c28b86762ea

Feed Name: McAfee Labs Blog

Threat Score
65/100

Date Published: 2023-08-04

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Mobile Research discovered an Android ad-fraud (Android/Clicker) library embedded in 43 Google Play apps (≈2.5M collective downloads) that uses a weeks-long latent period and Firebase remote resources to fetch and display ads while the device screen is off; the behavior abuses background and overlay permissions, drains battery and data, can distort advertising metrics and enable hidden click/phishing activity, and includes comprehensive IoCs (domains, package names, SHA256) with affected apps reported to Google.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.