Home Mobile White Ops Uncovers Advanced Mobile App Ad Fraud Scheme

White Ops Uncovers Advanced Mobile App Ad Fraud Scheme

SHARE:

Mobile ad fraudWhite Ops has uncovered a mobile ad fraud operation with unusually sophisticated and patient tactics to embed itself in mobile phones, the company said Thursday.

The investigation, dubbed CHARTREUSEBLUR (most of the 29 perpetrating apps used “blur” in the name, and apparently the White Ops threat research team is fond of the liqueur chartreuse), rounded up 29 fraudulent Google Play Store apps. All of which have since been removed, but not before collecting 3.5 million total downloads.

The apps in the fraud network, most of which were photo tools, enabled fraudulent impressions without tripping alarms.

“The reason we really wanted to put this out there is the increased sophistication of threat actors,” said Dina Haines, White Ops’ senior threat intelligence manager.

When consumers downloaded one of the photo apps, its codebase included a “stub app,” a placeholder developers use when they’re testing or planning additional code. The photo app would offer a basic function – like blurring photos or controlling the flash. But in the background, the stub app would load malicious code designed to serve ads and call up fake browser pages outside the user’s control.

Ads would display when phones were unlocked or while the phone was charging, for instance, Haines said.

Users couldn’t remove the app or even close it down in the background of their phone, she said, because it also removed its icon from the smartphone screen. So the only way to delete the app was to go into the phone settings, which most people wouldn’t think to do.

These fraudulent apps further diverted attention from themselves because they’d open a Chrome pop-up or site to show the ads. Users would therefore think the issue stemmed from the browser or a site or plug-in.

White Ops first detected one of these apps by noticing unusual download activity, indicating bot traffic, Haines said. They also had other common traits for malicious apps, including generic developer names that couldn’t be verified and a wave of initial five-star ratings (via bot sign-ups) followed by one-star reviews as actual people complained.

White Ops discovered the other 28 apps because the Chrome browser pages the apps all shared a common domain: ruanfan[.]co. An additional 99 apps share the same domain, and thus almost certainly have the same owner, Haines said.

White Ops isn’t pursuing attribution, which in the cyber security community means tying the fraud network back to the people who committed the crimes. But the shared domain is a potential lead, she said, especially considering the same bad actors and tactics will likely crop up again.

“Whether you call it cat-and-mouse or Whac-A-Mole, as we get better they improve,” she said.

Must Read

Paramount Skydance Merged Its Business – Now It’s Ready To Merge Its Tech Stack

Paramount Skydance, which officially turns 100 days old this week, released its first post-merger quarterly earnings report on Monday.

The Arena Group's Stephanie Mazzamaro (left) chats with ad tech consultant Addy Atienza at AdMonsters' Sell Side Summit Austin.

For Publishers, AI Gives Monetizable Data Insight But Takes Away Traffic

Traffic-starved publishers are hopeful that their long-undervalued audience data will fuel advertising’s automated future – if only they can finally wrest control of the industry narrative away from ad tech middlemen.

Q3: The Trade Desk Delivers On Financials, But Is Its Vision Fact Or Fantasy?

The Trade Desk posted solid Q3 results on Thursday, with $739 million in revenue, up 18% year over year. But the main narrative for TTD this year is less about the numbers and more about optics and competitive dynamics.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters
Comic: He Sees You When You're Streaming

IP Address Match Rates Are a Joke – And It’s No Laughing Matter

According to a new report, IP-to-email matches are accurate just 16% of the time on average, while IP-to-postal matches are accurate only 13% of the time. (Oof.)

Comic: Gamechanger (Google lost the DOJ's search antitrust case)

The DOJ And Google Sharpen Their Remedy Proposals As The Two Sides Prepare For Closing Arguments

The phrase “caution is key” has become a totem of the new age in US antitrust regulation. It was cited this week by both the DOJ and Google in support of opposing views on a possible divestiture of Google’s sell-side ad exchange.

create a network of points with nodes and connections, plain white background; use variations of green and grey for the dots and the connctions; 85% empty space

Alt Identity Provider ID5 Buys TrueData, Marking Its First-Ever Acquisition

ID5 bought TrueData mainly to tackle what ID5 CEO Mathieu Roche calls the “massive fragmentation” of digital identity, which is a problem on the user side and the provider side.