- GhostAd constantly requests ads, cannot be terminated.
- Millions of users affected by downloaded apps.
- Hidden by legitimate uses of advertising networks and Android.
The Check Point Harmony Mobile Detection Team has uncovered a group of Android applications on Google Play that pose as utilities and emoji tools. During an internal threat-hunting investigation, the team found the apps’ hid persistent background calls to advertising engines.
Apps continued running despite users closing them and after full reboot. The apps consumed battery power and mobile data without the user’s knowledge, but are not classifiable as malware as their methods were in line with Google Play Store policies and in line with Android development methods.
Researchers have named the campaign “GhostAd,” citing at least 15 apps, five of which remained on Google Play at the start of the investigation. Most downloads affected users in East and Southeast Asia, in particular the Philippines, Pakistan, and Malaysia, and collectively reached millions.
At one point, one of the apps was ranked second in the Play Store’s “Top Free Tools” category.
During the weeks during which the apps were live, users posted reviews describing constant pop-up ads, missing icons when attempting to uninstall, and phones that felt hot and less responsive.
Google has removed all the apps identified by the Check Point researchers. It says its Play Protect services now disables the named apps automatically on any device where they are installed.
GhostAd relied on several techniques to stay active. Apps launched a foreground service that continued running regardless of user actions, meeting Android app rules by displaying a notification of a running process, but leaving its contents blank. Apps also used JobScheduler to restart ad-loading tasks every few seconds. Therefore, even if the system terminated the running process, the scheduler would restart it.
The apps used several advertising SDKs in ways that generated constant, automated ad impressions, generating revenue for the app creators. Users complained of phones running hot, shorter battery life, and unexpected mobile data use.
The incident shows how legitimate tools can be deployed for large-scale misuse. GhostAd required no exploits, using existing permission frameworks, the ability to run in the background, and legal ad-serving services.
Given advertising frameworks designed to monetise the display of ads on users’ phones, and the use of ‘approved’ methods, it seems likely that similar events will re-occur. Companies running Android fleets may wish to consider device management software that limit the range of apps users can download and use. BYOD policies mean that users could be affected by similar apps, reducing device battery life and making the use of business applications less efficient.
Apps that examine and can block outgoing data on Android, including calls to third-party ad-servers, include NetGuard, Blokada, and the DuckDuckGo web browser.
(Image source: “The Ghost in You” by mandolin davis is licensed under CC BY-SA 2.0.)
Want to experience the full spectrum of enterprise technology innovation? Join TechEx in Amsterdam, California, and London. Covering AI, Big Data, Cyber Security, IoT, Digital Transformation, Intelligent Automation, Edge Computing, and Data Centres, TechEx brings together global leaders to share real-world use cases and in-depth insights. Click here for more information.
TechHQ is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
Author
- View all posts
Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.
