Uncovering a Large-Scale Fake Apps Adware Campaign on Google Play

    Date: 10/08/2026

    Severity: Medium

    Summary

    A large-scale fake Android app adware campaign involved more than 1,900 malicious applications installed across 500,000+ devices in 190+ countries, with India, Russia, and the U.S. among the most affected. The apps impersonated popular brands such as CapCut, Roblox, PayPal, Netflix, Zelle, and Xbox Game Pass, while sharing a common codebase and contacting the same remote server. Victims were redirected to advertising and subscription-fraud pages, with some charging up to $49.99 per month. Google removed the identified malicious apps from the Play Store. 

    Indicators of Compromise (IOC) List  

    Hash

    4f7b36963518e701276c77c1cad88d16fe64e8025c5223141c9af0eeb954ea63

    c56d49a2f323ca0333778964fd58a7399aa60c8136a6a178adc1f222747b353f

    2bdbd5c78a9d08b69983b965ae466210329b09eb26e5b491acdae9b822c729ab

    8cf714e0dab975c12cb5ac16837d7d2748a7f1672a3210a0e8e247dc405f8c68

    37539a20f07bd29e9285e7266ab29015c5467241bea43eee48f77769c42bbc7e

    d9ae6d844bf9269bee7d1f67f2f3d9e1d932974733068639c7204c2c92c391b1

    ba7a00fd597c04b7aa2efb59da853b1fcf34ba3bb63e7fbef2b9d9ef1a497641

    9b9e08b176d12c5e388b33c3e1fcdf2ba52b94cc6b310b56e3596eb783c26569

    b015de54db5073758909e5f3eaa90e73d7ff6f923195569d22395808b99a5557

    9a0881a67a7c35592216e0896e184d1ed960ef5c2280a6dafcfcbc0dcb29c099

    30a9f7461a0c11061b9349004f3dcd39ec763ec8bf1520ce655653fca67e183e

    ac46add9b7bb09779ab0a51924601e649431153c40d95c2ecc995e614ff2b89d

    83a95ceb22e24d5486f997d3ab7a8fa336cbf52c6489bfd20b285ccb16237f8e

    5d2c823acf6e719553688626a113e79842d186de7d3203c011b032eb2f87adca

    695eca22217b60b6218fbef51bcf660e569f7ce36c1d73a4646494d5489ae352

    3a50fa0ee7be36cbb1052254fbfdc0602abd7f52d69d7dc32d5c9ea6148ed16c

    18af2b9a1e9db5f85c789252dbb0048a244e0a181f88b31c0969e6789b9657b8

    78a098470a7926dc0bd36c625032fd421587aea88200fdbb877dbc655110c5f5

    601639168ac739e08fd267e86ba7eae440116e5b295fe01c00098bc2d9845405

    8a943f50417c53fd9d8f522fdb69d76c96ca386c2416a43d20f9181350282bd1

    84fac9f350cd9d627392125cd3b06bac62321a2a36954605bd4680383ee86ae2

    99122b355ba17d6fa55625414f9a48f8755f4a438374ce85c73c751e9f4fe6b6

    0022360894f15199c5f2fda5b5d8be3d26045d12ad50d80d02a23741601345af

    aa6883d64438a4374a5f44b5180d8ff12ca3d0c9423946df092420291007fdaf

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    sha256hash IN ("ac46add9b7bb09779ab0a51924601e649431153c40d95c2ecc995e614ff2b89d","18af2b9a1e9db5f85c789252dbb0048a244e0a181f88b31c0969e6789b9657b8","0022360894f15199c5f2fda5b5d8be3d26045d12ad50d80d02a23741601345af","b015de54db5073758909e5f3eaa90e73d7ff6f923195569d22395808b99a5557","601639168ac739e08fd267e86ba7eae440116e5b295fe01c00098bc2d9845405","9a0881a67a7c35592216e0896e184d1ed960ef5c2280a6dafcfcbc0dcb29c099","99122b355ba17d6fa55625414f9a48f8755f4a438374ce85c73c751e9f4fe6b6","d9ae6d844bf9269bee7d1f67f2f3d9e1d932974733068639c7204c2c92c391b1","30a9f7461a0c11061b9349004f3dcd39ec763ec8bf1520ce655653fca67e183e","4f7b36963518e701276c77c1cad88d16fe64e8025c5223141c9af0eeb954ea63","c56d49a2f323ca0333778964fd58a7399aa60c8136a6a178adc1f222747b353f","2bdbd5c78a9d08b69983b965ae466210329b09eb26e5b491acdae9b822c729ab","8cf714e0dab975c12cb5ac16837d7d2748a7f1672a3210a0e8e247dc405f8c68","37539a20f07bd29e9285e7266ab29015c5467241bea43eee48f77769c42bbc7e","ba7a00fd597c04b7aa2efb59da853b1fcf34ba3bb63e7fbef2b9d9ef1a497641","9b9e08b176d12c5e388b33c3e1fcdf2ba52b94cc6b310b56e3596eb783c26569","83a95ceb22e24d5486f997d3ab7a8fa336cbf52c6489bfd20b285ccb16237f8e","5d2c823acf6e719553688626a113e79842d186de7d3203c011b032eb2f87adca","695eca22217b60b6218fbef51bcf660e569f7ce36c1d73a4646494d5489ae352","3a50fa0ee7be36cbb1052254fbfdc0602abd7f52d69d7dc32d5c9ea6148ed16c","78a098470a7926dc0bd36c625032fd421587aea88200fdbb877dbc655110c5f5","8a943f50417c53fd9d8f522fdb69d76c96ca386c2416a43d20f9181350282bd1","84fac9f350cd9d627392125cd3b06bac62321a2a36954605bd4680383ee86ae2","aa6883d64438a4374a5f44b5180d8ff12ca3d0c9423946df092420291007fdaf")

    Reference:    

    Uncovering a Large-Scale Fake Apps Adware                                                        


    Tags

    MalwareAndroid MalwareAdwareIndiaRussiaUnited StatesRobloxPayPal

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags