Large-Scale Fraudulent Operations on Android

According to recent data, applications were discovered that loaded out-of-context ads onto users’ screens, making them difficult to remove.
Google has already removed these applications from the Play Store; however, at the peak of the malware’s activity, the number of requests exceeded 1.2 billion per day. Most of the infected applications linked to the IconAds campaign were distributed in Brazil, Mexico, and the United States. Some of them disguised themselves as Google Play or Google services to mislead users.
Although the applications have already been blocked, experts expect new variations of this threat in the near future.
Other schemes were also discovered in parallel. One of them was named Kaleidoscope. As part of this attack, attackers created two versions of the same application: a legitimate one for Google Play and a malicious copy for third-party sources. The malicious version launched intrusive ads and generated profit for fraudsters through fake impressions. This scheme was most widespread in Latin America, Turkey, Egypt, and India between December 2024 and May 2025. A significant part of the financial benefit from these attacks was associated with the company Saturn, which offers tools for ad and video monetization.
Another dangerous trend was the use of NFC technology in the malicious applications NGate and SuperCard X. Through infected smartphones, attackers were able to transmit victims’ bank card signals and thus withdraw money remotely. In addition, the Qwizzserial campaign became more active, distributing fake banking applications through Telegram by disguising them as government services. As a result of this malware, two-factor authentication codes, banking data, and other confidential information were stolen, causing damages of tens of thousands of dollars.
The scale of these attacks indicates that cybersecurity today must be an integral part of the activities of any company and every user. Regular checks of digital protection are a critical condition for countering malware and ensuring data security.