{"id":4166,"date":"2025-07-29T15:41:33","date_gmt":"2025-07-29T13:41:33","guid":{"rendered":"https:\/\/www.mobisec.com\/?p=4166"},"modified":"2025-07-29T15:41:33","modified_gmt":"2025-07-29T13:41:33","slug":"mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025","status":"publish","type":"post","link":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/","title":{"rendered":"Mobile fraud: the wave of mobile ad fraud in 2025"},"content":{"rendered":"<p>In 2025, mobile security threats have evolved dramatically, exploiting the spread of Android apps, BYOD, and reliance on official marketplaces. The <strong>IconAds<\/strong>, mobile fraud operation represents a case in point: <strong>more than 350 infected Android apps, 1.2 billion fraudulent ad requests per day<\/strong>, and an adaptive capability that has been overcoming Play Store controls for years.<\/p>\n<p>But IconAds is just the tip of the iceberg. The mobile ecosystem is becoming a breeding ground for malware capable of generating advertising, financial and identity theft fraud. <strong>It is time for IT decision makers to address mobile security with a mature, structured and proactive approach.<\/strong><\/p>\n<h2 style=\"margin-top: 50px;\">IconAds: how new mobile fraud works<\/h2>\n<p>IconAds presents itself as a highly organized <strong>mobile ad fraud operation.<\/strong> The apps involved, also published in the Google Play Store, hide the icon from the launcher and display out-of-context advertisements that are part of mobile ad <strong>fraud campaigns<\/strong>. This behavior reduces usability, hinders app removal, and, most importantly, generates illicit ad revenue.<\/p>\n<p>Some apps even go so far as to <strong>simulate the icon of the Play Store or official Google apps<\/strong> to induce the user to click and trigger fraudulent activity in the background.<br \/>\nTo avoid expert analysis, IconAds disables malicious features if it detects that the app was installed from unofficial sources (sideloading). A resilient, dynamic network that is difficult to dismantle, with a massive fraudulent traffic base, particularly from <strong>Brazil, Mexico, and the United States.<\/strong><\/p>\n<h2 style=\"margin-top: 50px;\">The Kaleidoscope case: the good twin and the evil twin<\/h2>\n<p>In parallel, another campaign known as <strong>Kaleidoscope<\/strong> exploits a deceptive technique:<strong> twin deception.<\/strong><br \/>\nTwo nearly identical versions of the same app are distributed:<\/p>\n<ul>\n<li>one harmless (available on Google Play)<\/li>\n<li>the other malicious (distributed on alternative stores or fake sites)<\/li>\n<\/ul>\n<p>The malicious app <strong>generates invasive ads and fraudulent ad traffic<\/strong>, but it exploits the same app ID as the legitimate version. The result is a flow of illicit earnings and, at the same time, a compromise of device performance and the reputation of the real developers.<\/p>\n<p>This technique, born out of the earlier \u201cKonfety\u201d scheme, has been adopted by groups active in <strong>Latin America, Turkey, Egypt, and India<\/strong>, where the use of unofficial stores is widespread.<\/p>\n<h2 style=\"margin-top: 50px;\">From advertising fraud to financial fraud<\/h2>\n<p>Mobile fraud today does not stop at advertising. Malware such as <strong>NGate, SuperCard X and Ghost Tap<\/strong> use NFC technology to hijack contactless card signals and generate fraudulent transactions remotely, bypassing normal security controls.<\/p>\n<p>Added to this are campaigns such as <strong>Qwizzserial<\/strong>, which has infected over 100,000 devices in Uzbekistan by intercepting bank SMS messages and credentials, and <strong>SparkKitty<\/strong>, spyware active in Asia that uses OCR to search for images containing crypto wallet recovery phrases.<\/p>\n<h2 style=\"margin-top: 50px;\">Why is mobile fraud a threat to your business?<\/h2>\n<p>Many CISOs and IT managers underestimate the mobile perimeter, focusing resources on desktop endpoints and cloud infrastructure. But today, the biggest risks can come from:<\/p>\n<ul>\n<li>a malicious app installed on a BYOD device<\/li>\n<li>a manipulated ad campaign that leverages infected SDKs<\/li>\n<li>malware that exfiltrates corporate data from a clone app installed by a co-worker<\/li>\n<\/ul>\n<h2 style=\"margin-top: 50px;\">What you can do against mobile fraud: concrete defenses<\/h2>\n<ul>\n<li><strong>UEM and centralized endpoint management:<\/strong> an advanced UEM platform allows you to monitor installed apps, active permissions, and abnormal behavior on devices, including personal (BYOD), in real time.<\/li>\n<li><strong>Training and store monitoring:<\/strong> it is essential to train teams on the risks of counterfeit apps and unofficial sources. Even the informed user can be misled by a fake icon.<\/li>\n<li><strong>App vetting and mobile threat intelligence:<\/strong> Mobisec offers services to analyze app runtime behavior, identifying anomalous activity such as unauthorized access, suspicious obfuscation, or communication with unknown servers.<\/li>\n<\/ul>\n<h3 style=\"margin-top: 50px;\">DLP and Zero Trust applied to mobile<\/h3>\n<p>A mobile policy should include:<\/p>\n<ul>\n<li>session isolation for unmanaged devices<\/li>\n<li>MFA authentication<\/li>\n<li>blocking download\/copy\/use of camera when accessing sensitive data<\/li>\n<\/ul>\n<h2 style=\"margin-top: 50px;\">Defend your devices. Protect your business.<\/h2>\n<p>Mobisec supports you with:<\/p>\n<ul>\n<li><strong>UEM with complete visibility into enterprise devices and BYOD<\/strong><\/li>\n<li><strong>Threat detection and behavioral analysis services<\/strong><\/li>\n<li><strong>Customized consulting to integrate mobile security into your IT strategy<\/strong><\/li>\n<\/ul>\n<blockquote class=\"blockquote-stile-alt\"><p><a class=\"cursor-pointer\" href=\"https:\/\/www.mobisec.com\/en\/contacts\/\" target=\"_blank\" rel=\"noopener\">Get a consultation with one of our experts<\/a><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>In 2025, mobile security threats have evolved dramatically, exploiting the spread of Android apps, BYOD, and reliance on official marketplaces. The IconAds, mobile fraud operation represents a case in point: more than 350 infected Android apps, 1.2 billion fraudulent ad requests per day, and an adaptive capability that has been overcoming Play Store controls for [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"class_list":["post-4166","post","type-post","status-publish","format-standard","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Mobile fraud: the wave of mobile ad fraud in 2025 | Mobisec<\/title>\n<meta name=\"description\" content=\"352 infected apps, mobile fraud, malware, and large-scale fake apps: a guide to protecting your endpoints in 2025.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mobile fraud: the wave of mobile ad fraud in 2025 | Mobisec\" \/>\n<meta property=\"og:description\" content=\"352 infected apps, mobile fraud, malware, and large-scale fake apps: a guide to protecting your endpoints in 2025.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/\" \/>\n<meta property=\"og:site_name\" content=\"Mobisec\" \/>\n<meta property=\"article:published_time\" content=\"2025-07-29T13:41:33+00:00\" \/>\n<meta name=\"author\" content=\"lara.milani\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"lara.milani\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/news\\\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/news\\\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\\\/\"},\"author\":{\"name\":\"lara.milani\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/#\\\/schema\\\/person\\\/d06ccaf0f247debac0d3db423e389fd5\"},\"headline\":\"Mobile fraud: the wave of mobile ad fraud in 2025\",\"datePublished\":\"2025-07-29T13:41:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/news\\\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\\\/\"},\"wordCount\":677,\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/news\\\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\\\/\",\"url\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/news\\\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\\\/\",\"name\":\"Mobile fraud: the wave of mobile ad fraud in 2025 | Mobisec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/#website\"},\"datePublished\":\"2025-07-29T13:41:33+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/#\\\/schema\\\/person\\\/d06ccaf0f247debac0d3db423e389fd5\"},\"description\":\"352 infected apps, mobile fraud, malware, and large-scale fake apps: a guide to protecting your endpoints in 2025.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/news\\\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.mobisec.com\\\/en\\\/news\\\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/news\\\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Homepage\",\"item\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mobile fraud: the wave of mobile ad fraud in 2025\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/\",\"name\":\"Mobisec\",\"description\":\"Protect your mobile security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.mobisec.com\\\/en\\\/#\\\/schema\\\/person\\\/d06ccaf0f247debac0d3db423e389fd5\",\"name\":\"lara.milani\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/62ca5c468cf06bc537908c12fe0565e062b66c83a015756acbfe10abdc1b3cad?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/62ca5c468cf06bc537908c12fe0565e062b66c83a015756acbfe10abdc1b3cad?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/62ca5c468cf06bc537908c12fe0565e062b66c83a015756acbfe10abdc1b3cad?s=96&d=mm&r=g\",\"caption\":\"lara.milani\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mobile fraud: the wave of mobile ad fraud in 2025 | Mobisec","description":"352 infected apps, mobile fraud, malware, and large-scale fake apps: a guide to protecting your endpoints in 2025.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/","og_locale":"en_US","og_type":"article","og_title":"Mobile fraud: the wave of mobile ad fraud in 2025 | Mobisec","og_description":"352 infected apps, mobile fraud, malware, and large-scale fake apps: a guide to protecting your endpoints in 2025.","og_url":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/","og_site_name":"Mobisec","article_published_time":"2025-07-29T13:41:33+00:00","author":"lara.milani","twitter_card":"summary_large_image","twitter_misc":{"Written by":"lara.milani","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/#article","isPartOf":{"@id":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/"},"author":{"name":"lara.milani","@id":"https:\/\/www.mobisec.com\/en\/#\/schema\/person\/d06ccaf0f247debac0d3db423e389fd5"},"headline":"Mobile fraud: the wave of mobile ad fraud in 2025","datePublished":"2025-07-29T13:41:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/"},"wordCount":677,"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/","url":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/","name":"Mobile fraud: the wave of mobile ad fraud in 2025 | Mobisec","isPartOf":{"@id":"https:\/\/www.mobisec.com\/en\/#website"},"datePublished":"2025-07-29T13:41:33+00:00","author":{"@id":"https:\/\/www.mobisec.com\/en\/#\/schema\/person\/d06ccaf0f247debac0d3db423e389fd5"},"description":"352 infected apps, mobile fraud, malware, and large-scale fake apps: a guide to protecting your endpoints in 2025.","breadcrumb":{"@id":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.mobisec.com\/en\/news\/mobile-fraud-the-wave-of-mobile-ad-fraud-in-2025\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Homepage","item":"https:\/\/www.mobisec.com\/en\/"},{"@type":"ListItem","position":2,"name":"Mobile fraud: the wave of mobile ad fraud in 2025"}]},{"@type":"WebSite","@id":"https:\/\/www.mobisec.com\/en\/#website","url":"https:\/\/www.mobisec.com\/en\/","name":"Mobisec","description":"Protect your mobile security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mobisec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.mobisec.com\/en\/#\/schema\/person\/d06ccaf0f247debac0d3db423e389fd5","name":"lara.milani","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/62ca5c468cf06bc537908c12fe0565e062b66c83a015756acbfe10abdc1b3cad?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/62ca5c468cf06bc537908c12fe0565e062b66c83a015756acbfe10abdc1b3cad?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/62ca5c468cf06bc537908c12fe0565e062b66c83a015756acbfe10abdc1b3cad?s=96&d=mm&r=g","caption":"lara.milani"}}]}},"_links":{"self":[{"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/posts\/4166","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/comments?post=4166"}],"version-history":[{"count":2,"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/posts\/4166\/revisions"}],"predecessor-version":[{"id":4168,"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/posts\/4166\/revisions\/4168"}],"wp:attachment":[{"href":"https:\/\/www.mobisec.com\/en\/wp-json\/wp\/v2\/media?parent=4166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}