SlopAds Hits 38 Million Downloads With Malicious Android Apps

17 Sep 2025

A sophisticated mobile ad fraud operation, known as SlopAds, recently penetrated the Google Play Store with 224 malicious applications, collectively garnering over 38 million downloads across 228 countries and territories. The operation employed advanced techniques such as steganography and multi-layered obfuscation to deliver fraudulent advertising payloads while skillfully evading detection.

Conditional Fraud Activation

The SlopAds campaign utilized a conditional fraud system, activating its malicious payloads only when users installed apps through specific advertising channels rather than organic visits to the Play Store. This tactic allowed the apps to maintain a guise of legitimacy, staying on the platform longer despite their fraudulent nature. According to Human Security analysts, the operation orchestrated approximately 2.3 billion fraudulent bid requests daily at its peak, with significant traffic from the United States, India, and Brazil.

Exploiting Development Services

The fraudulent apps took advantage of legitimate development services, notably Firebase Remote Config, to retrieve encrypted configuration data. This data contained URLs pointing to the download of the primary fraud module, termed 'FatModule'. The delivery of these payloads relied on digital steganography, where command-and-control servers dispatched specially crafted PNG files embedded within encrypted ZIP archives. Upon decryption and reassembly, these images revealed APK components forming the complete FatModule.

Advanced Anti-Analysis Techniques

FatModule was designed with multiple anti-analysis measures to thwart detection and examination. These techniques included recognition of debugging and hooking frameworks (searching for terms like 'hook', 'Xposed', and 'Frida'), string encryption, and packed native code, all aimed at inhibiting both static and dynamic analysis. Fraud execution occurred within concealed WebViews, which meticulously collected device fingerprinting data, such as hardware specifications and GPU details, to enable accurate targeting of fraudulent activities. These hidden interfaces then directed to attacker-owned cashout domains, seamlessly generating fraudulent ad impressions and clicks without user knowledge.

In response to these malicious activities, Google has removed the identified SlopAds applications from its Play Store. To further safeguard its users, Google Play Protect automatically warns against and blocks the installation of known malicious apps, inclusive of those involved in this campaign.

Top charts for Mobile Android

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6791032
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1451636
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
595689
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
466416
downloads

News and reviews for Mobile Android

Roadtrip Apps Transform Long Drives for Android Users

Android roadtrip apps enhance navigation, itineraries, fuel tracking and entertainment, streamlining long drives.

Read more

Upgrade Transforms NotebookLM Android with AI Enhancements

Google's NotebookLM for Android now features AI-powered multimedia handling, enhancing productivity with new mobile-centric tools.

Read more

Google Introduces Incognito Mode to Android App

Google app on Android now supports Incognito, enhancing privacy by encrypting searches and limiting data leaks.

Read more

Google App Adds Privacy Feature on Android

Google app for Android introduces 'Search History Off' toggle, enhancing user privacy. Expected rollout worldwide in coming months.

Read more

BuzzKill App Optimizes Android Notifications for Focus

BuzzKill, privacy-focused, adjusts Android notifications. Available now, it helps focus by reducing distractions.

Read more

Trackers in Android Apps Raise Privacy Concerns

Hidden trackers in Android apps spark privacy concerns. Apps like TrackerControl help identify and block these trackers, boosting defenses.

Read more

Epic Games Offers Darkside Detective for Free on Mobile

Darkside Detective now free on mobile through Epic Games until 2023-12-11, saving users $13.98.

Read more

Google Expands Autofill in Chrome for Seamless Form Filling

Google updates Chrome Autofill: now supports vehicle details in Google Wallet for easier form filling across devices.

Read more

Highlight Android Deals: Boxville Discounts Today

Today's Android deals cover Boxville 1, Boxville 2, Dungeon Defense, and more. Prices changing quickly.

Read more

DeckSettings App Enhances Steam Deck Game Compatibility Reference

DeckSettings improves Steam Deck game compatibility, offering critical playability info with Android availability and iOS beta on the horizon.

Read more