logo

'Konfety' Ad Fraud Uses 250+ Google Play Decoy Apps to Hide Malicious Twins

ID: 2e9795cf-2148-5b0a-b21b-383d2439c141

STIX ID: report--2e9795cf-2148-5b0a-b21b-383d2439c141

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-07-16

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

HUMAN Security uncovered the Konfety ad-fraud operation in which threat actors publish benign 'decoy' apps on Google Play and distribute malicious 'evil twin' versions through malvertising and compromised sites; the evil twins abuse the CaramelAds SDK to serve fraudulent ads at scale (peaking at ~10 billion requests/day), monitor user searches, sideload additional payloads, hide app icons, and establish C2 communications, enabling sustained large-scale ad fraud and privacy compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.