Over 300 malicious apps involved in ad fraud and credentials and credit card data theft have been installed over 60 million times from Google Play Store over the past year.
“Threat Lab has identified over 180 app IDs since early 2024 as part of the Vapor scheme, collectively amassing over 56 million downloads and generating over 200 million bid requests daily, with no real functionality delivered to users,” IAS Threat Lab stated.
Cybersecurity firm Bitdefender also identified additional apps involved in the massive ad fraud campaign dubbed “Vapor,” pushing the number to 331.
Malicious apps on Google Play Store involved in ad fraud and data theft
According to IAS, over 180 malicious apps were involved in the ad fraud campaign, generating over 200 million advertising requests daily.
Most malicious apps deployed under the Vapor ad fraud campaign purport to offer specialized functionality such as fitness tracking, battery optimization, note taking, and QR scanning, while others promise to offer sensitive services such as healthcare.
However, they provide “no real functionality” except engaging in ad fraud by displaying “endless, intrusive full-screen interstitial video ads.”
“The apps display out-of-context ads and even try to persuade victims to give away credentials and credit card information in phishing attacks,” noted Bitdefender.
According to Bitdefender, the malicious apps mostly target users in Brazil, the United States, Mexico, Turkey, and South Korea.
They pass the Google Play Store review process because they do not pack malware but download additional payloads from the threat actors’ command and control servers via updates.
Similarly, the malicious apps sometimes disable their Launcher Activity in the AndroidManifest.xml file to become invisible on the home screen. Some also use Android TV launchers to hide on Android settings or rename themselves to known legitimate apps to avoid detection.
Additionally, they launch without user interaction while keeping their icons hidden. They also use native code to download additional components to avoid detection.
The malicious apps bypass ‘SYSTEM_ALERT_WINDOW’ restrictions in newer Android versions to display a secondary full-screen display that shows the fraudulent ads by overlaying other apps. They also disable the ‘Back’ button to prevent users from exiting.
“With the app fully set up, it immediately attempts to barrage the user with full-screen interstitial ads, effectively hijacking the device’s screen and rendering the user’s device largely inoperative,” IAS stated.
Similarly, the apps clear themselves from “recent tasks” to prevent Android users from knowing which apps had launched the intrusive ads.
Additionally, the ad fraud campaign extends to credential theft by displaying fake YouTube and Facebook login screens to steal login details. The apps also prompt users to enter credit card details using various enticing phishing lures.
According to IAS Threat Labs, the malicious actors uploaded the apps mostly between August 2024 and March 2025 using various developer accounts that hosted only a few apps to avoid raising suspicion.
“Fraudsters behind the Vapor operation have created multiple developer accounts, each hosting only a handful of apps to distribute their operation and evade detection,” IAS wrote. “This distributed setup ensures that the takedown of any single account would have minimal impact on the overall operation.”
Apps involved in the ad fraud campaign with over 1 million downloads include AquaTracker, ClickSave Downloader, Scan Hawk, Be More, and Water Time Tracker. Others, such as BeatWatch, Translate Scan, and Handset Locator, had between 500,000 and 50,000 installs.
Malicious apps removed by Google
Meanwhile, Google has removed all the offending apps involved in the ad fraud campaign from its official store. Google Play Protect also warns users and disables already-downloaded malicious apps, even if they originated from third-party stores.
However, chances are that some malicious apps still exist on Google Play Store as the threat actors employ highly evasive tactics to avoid detection. Bitdefender also cautions that the ad fraud campaign is still ongoing.
“To be clear, this is an active campaign. The latest malware published in the Google Play Store went live in the first week of March 2025. When we finished the investigation, a week later, 15 applications were still available for download on Google Play,” Bitdefender warned.

