'Konfety' Ad Fraud Uses 250+ Google Play Decoy Apps to Hide Malicious Twins
ID: 2e9795cf-2148-5b0a-b21b-383d2439c141
STIX ID: report--2e9795cf-2148-5b0a-b21b-383d2439c141
Feed Name: The Hacker News
HUMAN Security uncovered the Konfety ad-fraud operation in which threat actors publish benign 'decoy' apps on Google Play and distribute malicious 'evil twin' versions through malvertising and compromised sites; the evil twins abuse the CaramelAds SDK to serve fraudulent ads at scale (peaking at ~10 billion requests/day), monitor user searches, sideload additional payloads, hide app icons, and establish C2 communications, enabling sustained large-scale ad fraud and privacy compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
