Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

OpenAI’s “Embarrassing” Mathematics | Tech Crunch

Whitehouse is already one of the most blocked accounts on Bluesky

Europol dismantles SIM farm network running 49 million fake accounts worldwide

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Slopads Shrink Ring exploits 224 Android apps to drive 2.3 billion ad bids every day
Identity

Slopads Shrink Ring exploits 224 Android apps to drive 2.3 billion ad bids every day

userBy userSeptember 16, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 16, 2025Ravi LakshmananAdvertising fraud / Mobile security

Called massive ad fraud and click fraud operations, Slopads ran a cluster of 224 apps, attracting 308 million downloads in 228 countries and regions.

“These apps use steganography to provide fraud payloads, create hidden web views, navigate to threaten actor-owned cash out sites, and generate impressions and clicks of fraudulent ads,” the Human’s Satori Threat Intelligence and Research team said in a report shared with Hacker News.

The name “Slopads” gives a nod to the mass-productivity potential of apps and the use of artificial intelligence (AI)-themed services such as StabledIffsion, Aiguide, and ChatGlm hosted by threat actors on Command-and-Control (C2) servers.

Audit and subsequent

The company said the campaign accounted for 2.3 billion bid requests per day at its peak, with traffic mainly from the Slopads app originating from the US (30%), India (10%) and Brazil (7%). Since then, Google has removed all the problem apps from the Play Store, effectively confusing the threat.

What sets your activity apart is when Slopads-related apps are downloaded, by querying the Mobile Marketing Attribution SDK to see if they were downloaded directly from the Play Store (i.e. organically) or if they are the result of users (IE, non-operational) who clicked on the ads redirected to the Play Store list.

The fraudulent behavior only starts in scenarios where the app is downloaded after ad clicks, downloading the ad fraud module, Fatmodule, from the C2 server. On the other hand, if it was originally installed, the app will work as advertised on the App Store page.

“From developing and publishing apps that have committed fraud under certain circumstances to adding layers above the obfuscation layer, Slopads reinforces the notion that threats to the digital advertising ecosystem are merely sophisticated,” the human researcher said.

“This tactic creates a more complete feedback loop for threat actors and only causes fraud if there is reason to believe the device has not been investigated by security researchers. It fuses malicious traffic into legitimate campaign data, complicating detection.”

Fatmodule is delivered by four PNG image files that hide the APK, decrypted, reassembled and enforced AD scams using hidden WebViews to collect device and browser information.

CIS Build Kit

“One cash-out mechanism for Slopads is through HTML5 (H5) games and news websites owned by threat actors,” the human researcher said. “These gaming sites frequently display ads and hide the WebView on which the site is loaded, allowing sites to monetize the impressions and clicks of many ads before the WebView closes.”

Domains promoting the Slopad app are known to link to another domain AD2[.]CC functions as a Tier-2 C2 server. Overall, an estimated 300 domains have been identified that promote such apps.

This development will be just over two months after humans flag another set of 352 Android apps as part of the AD fraud scheme’s codename ICONADS.

“Slopads highlights the evolving refinement of mobile ad fraud, including the execution of stealth conditional fraud and the ability to quickly scale,” said Gavin Reid, CISO at Human.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSalesforce has launched Missionforce, a “national security-centric business unit.”
Next Article YouTube announces new generation AI tools for short pants creators
user
  • Website

Related Posts

Europol dismantles SIM farm network running 49 million fake accounts worldwide

October 19, 2025

New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs

October 18, 2025

Silver Fox spreads Winos 4.0 attack to Japan and Malaysia via HoldingHands RAT

October 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

OpenAI’s “Embarrassing” Mathematics | Tech Crunch

Whitehouse is already one of the most blocked accounts on Bluesky

Europol dismantles SIM farm network running 49 million fake accounts worldwide

Wikipedia says AI search summaries and social videos are causing traffic decline

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.