These apps are part of a new advertising fraud campaign called 'Scylla,' generating revenue by 'impersonating legitimate applications and displaying ads.' Essentially, Scylla apps use mismatched IDs to present themselves to advertisers as if the clicks/impressions originate from more lucrative software categories.
85 fraudulent applications found on both the App Store and Google Play Store
HUMAN's researchers discovered 29 Scylla apps 'imitating' up to 6,000 apps based on CTV and regularly cycling through IDs to evade fraud detection.
Additionally, security researchers believe that Scylla marks the third wave of an operation they initially detected in August 2019, dubbed 'Poseidon.' The second wave seemingly emanated from the same threat actor, dubbed 'Charybdis,' reaching its peak at the end of 2020.
Below is a list of 10 adware software found on the iOS App Store:
- Loot the Castle - com.loot.rcastle.fight.battle (id1602634568)
- Run Bridge - com.run.bridge.race (id1584737005)
- Shinning Gun - com.shinning.gun.ios (id1588037078)
- Racing Legend 3D - com.racing.legend.like (id1589579456)
- Rope Runner - com.rope.runner.family (id1614987707)
- Wood Sculptor - com.wood.sculptor.cutter (id1603211466)
- Fire-Wall - com.fire.wall.poptit (id1540542924)
- Ninja Critical Hit - wger.ninjacriticalhit.ios (id1514055403)
- Tony Runs - com.TonyRuns.game
https://Mytour.vn/85-ung-dung-gian-lan-duoc-tim-thay-tren-app-store-va-google-play-store-30614n.aspx
Apple and Google have promptly removed these apps from their respective stores upon receiving reports. In case users inadvertently download and install any of these apps, simply deleting them from their devices suffices.
