Hidden Google Play Adware Drains Devices and Disrupts Millions of Users

Nov. 27, 2025, 7:20 p.m.

Description

A large-scale Android adware campaign dubbed 'GhostAd' has been uncovered, affecting millions of users primarily in East and Southeast Asia. The campaign involved multiple apps on Google Play that appeared harmless but created persistent background advertising engines, draining device resources and disrupting normal phone use. These apps used foreground services, job schedulers, and continuous ad refreshing to maintain their presence even after users closed or rebooted their devices. The adware integrated multiple legitimate advertising SDKs but violated fair-use policies by continuously loading ads without user interaction. Users experienced battery drain, reduced performance, and difficulty in removing the apps. Google has since removed the identified apps from the Play Store and disabled them via Google Play Protect.

Date

  • Created: Nov. 27, 2025, 6:32 p.m.
  • Published: Nov. 27, 2025, 6:32 p.m.
  • Modified: Nov. 27, 2025, 7:20 p.m.

Indicators

  • ebd4365923964218caa24c9f88f009aefa7f1427a20f0f02927c98285734dae5
  • a039c862807a14482169db0db5904749b7e5d733807418430d1cc3c2e3724f96
  • 91eb6afb903b2155246cb64289b4c2554922e0472fb355091843e0138c91a114
  • 7185a439005033b45b48294b302973898e68d8c898003f98acc275b27948ad40
  • 13805e77fb44a5a5af829f13ee494b9cfc4d5c9b470d51014cd506bd40c57426

Attack Patterns

  • GhostAd

Additional Informations

  • Malaysia
  • Philippines
  • Pakistan