Android Wallpaper Apps Found Running Ad Fraud Scheme

Trend Micro has detected 15 Android wallpaper apps in the Google Play Store running click fraud schemes. So far, these apps have been downloaded well over 200,000 times. The heaviest concentration of victims were found in Italy, Taiwan, the United States, Germany, and Indonesia. Google has since removed these malicious apps from the Play Store. Click fraud is a type of fraud that takes advantage of pay per click online advertising.

Basically, the fraudster automates the clicks that would normally be a human being clicking on an ad, thus generating revenue for false clicks. Once the malware is installed, the app decodes the C2 server address for configurations and launches an HTTP GET request which communicates with the C2 for a JSON-formatted list. Next, the app gets the advertising ID from the Google Play Services and replaces some parameters on the device. The URL is then loaded and then it begins to simulate clicks on the ad page. For further details, view Trend Micro’s report.

Indicators of Compromise

SHA256

C&C Server

  • http://myukka.com/v2/xfeeds.php
  • http://198.1.125.77/tracking/config.php

Duncan Newell

Duncan is a technology professional with over 20 years experience of working in various IT roles. He has a interest in cyber security, and has a wide range of other skills in radio, electronics and telecommunications.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: