Skip to content

Android users issued warning to delete apps immediately after cyber attack infestation

Express • December 21, 2025

Android users have been warned to delete certain apps immediately after cyber criminals launched a large-scale attack that infected millions of devices worldwide. Security researchers say hackers targeted Android phones through a sophisticated advertising fraud scheme designed to slow devices down and secretly generate money through fake advert clicks.

Victims were unaware their phones had been compromised while malicious adverts ran in the background.

Set Daily Express as a 'Preferred Source' to get quicker access to the news you value.

The attack, uncovered by HUMAN’s Satori Threat Intelligence and Research Team, has been dubbed “SlopAds”.

Researchers identified 224 infected Android apps, which were downloaded more than 38 million times through the Google Play Store across 228 countries and territories.

Security specialists said the apps used advanced techniques, including steganography, to hide malicious code inside images.

Once installed, the apps created hidden web views that silently loaded hacker-controlled websites to generate fraudulent ad impressions and clicks.

In a statement, the Satori Threat Intelligence and Research Team said: “HUMAN’s Satori Threat Intelligence and Research Team has uncovered and disrupted a sophisticated ad fraud and click fraud operation dubbed SlopAds.

"The threat actors operate a collection of 224 apps and growing, collectively downloaded from Google Play more than 38 million times.”

Google has since removed all affected apps from the Play Store, preventing new users from downloading them. However, experts warn that existing users must manually delete any compromised apps still installed on their devices.

Users who downloaded one of the infected apps are expected to receive an alert advising them to remove it immediately, according to reports.

To protect against future threats, Android users are being urged to ensure Google Play Protect remains switched on. The security feature scans apps before installation and blocks those linked to known malicious behaviour, including SlopAds-style fraud.

Google warned that ad fraud causes widespread harm beyond individual users.

“Ad interactions generated to trick an ad network into believing traffic is from genuine user interest is ad fraud,” the company said.

“Invalid traffic and ad fraud is harmful to advertisers, developers and users, and leads to long-term loss of trust in the mobile ads ecosystem.”

Extracted Entities

Attack Types (2)

Campaigns (1)

Platforms (1)