Global Scam IntelligenceDaily updates on global scam news and tactics
Back to home
PhishingPublished: July 28, 2026🌐

New Android Malware Uses Overlay Technique to Display Ads After Phone Calls

Security researchers have discovered a new form of Android malware that exploits an overlay technique to display advertisements across the entire phone screen immediately after calls end. The malicious apps use system permissions to block regular functions, generating fraudulent ad revenue. Experts warn this technique could be adapted for phishing attacks to steal login credentials in the future.

Malware Overview and Tactics

The newly discovered malware disguises itself as a legitimate application but activates malicious functions after installation. Its primary feature is the "overlay technique," which displays advertisements across the entire phone screen at the moment a call ends, disrupting normal smartphone operation.

Infection Mechanism

The infection process unfolds as follows:

  1. Deceptive Appearance: The malware-infected app poses as harmless utility software or tools
  2. Permission Requests: During installation, it requests extensive system control permissions, including the ability to display content over other apps (overlay permission)
  3. Dormancy and Activation: The app remains quiet immediately after installation, then exploits system-level permissions to activate its harmful functions
  4. Timing Exploitation: Advertisements are displayed immediately after calls end, when users are most likely to check their screens

Security researchers emphasize that this timing choice is deliberate. When users return from a call and unlock their screens or navigate to the home screen, they are more likely to accidentally click on the displayed advertisements, generating fraudulent ad revenue for the perpetrators.

Potential Dangers

Although the malware currently aims at generating fraudulent ad revenue, security experts have raised serious concerns:

  • Application to Phishing Fraud: The overlay technique could be used to display fake login screens over legitimate banking apps or social networks, stealing user account credentials
  • Personal Information Theft: Malware with device control capabilities could access contacts, messages, location data, and other sensitive information
  • Severe System Compromise: Once malware obtains overlay permissions, it can potentially gain complete control over device operations

How to Check if Your Device is Infected

If you observe the following symptoms, your device may be infected:

  • Unrecognized advertisements appear across the entire screen immediately after calls end
  • Advertisements appear without opening any app
  • Your smartphone's performance slows down abnormally
  • Battery drains rapidly
  • Unknown apps appear in your app list

Protection Strategies

Careful App Selection

  • Trusted Sources Only: Install apps exclusively from official app stores like Google Play
  • Verify Developer Identity: Research the app developer's reputation before installation
  • Read User Reviews: Check for warning signs in reviews, such as "too many ads" or "strange screens appear"
  • Avoid Unknown Sources: Never install apps from unverified providers

Permission Review During Installation

The most critical defense is carefully scrutinizing the permissions each app requests:

  • If an app requests permission to "display over other apps," question whether this is truly necessary for its function
  • Be suspicious of apps like calculators or flashlights requesting unusually broad permissions
  • After installation, review each app's permissions in your device settings and revoke unnecessary access

Regular Maintenance

  • Update OS and Apps: Keep Android OS and all applications current. Updates include critical security patches
  • Remove Unused Apps: Uninstall applications you no longer use
  • Permission Audit: Check your device settings monthly to review which permissions you've granted to each app

If Your Device is Compromised

If abnormal advertisements are detected:

  1. Open the Settings menu and navigate to "Apps" or "Application Management"
  2. Identify suspicious apps (recently installed apps or unfamiliar applications)
  3. Check their permissions, particularly the "display over other apps" setting
  4. Revoke the problematic permission and uninstall the app
  5. If issues persist, completely remove the suspected app

Reporting Channels

If you suspect infection or experience damages, contact:

  • Government Agencies: Information Security Help Desk (国の情報セキュリティ相談窓口)
  • Mobile Carriers: Customer support of your service provider (NTT Docomo, au, SoftBank, etc.)
  • Google: Google Play Security Report and reporting features
  • Law Enforcement: Local police or cybercrime consultation hotline if damages have occurred

Conclusion

This malware represents a sophisticated and evolving threat targeting smartphones—devices people carry constantly. Security researchers classify it as an "imminent threat" because its techniques could be adapted for phishing and other fraud schemes. The strongest defense is maintaining constant vigilance regarding app permissions during installation.

Source: ad-hoc-news.de

Share