DoubleVerify uncovers AfterCall scheme generating millions of fraudulent Android impressions
DoubleVerify has identified a fraudulent Android ad scheme called "AfterCall," which leverages system permissions to display intrusive ads immediately following phone calls. The tactic enables apps to generate hundreds of millions of impressions, creating significant brand safety and reputation risks for advertisers.
Key Takeaways
- Fraudulent apps exploit the 'display over other apps' permission to trigger full-screen ads when a phone call returns to an idle state.
- The scheme generates hundreds of millions of impressions monthly across dozens of unique Android applications.
- Developers use evasion tactics including hiding apps from the recent apps list and using deceptive utility icons like clocks or calendars.
- AI-powered detection is required to identify the fraud because the underlying Android 'Intents' are also used by legitimate caller ID services.
Why It Matters
This discovery highlights a pivot in mobile ad fraud toward 'out-of-context' inventory that reaches real users in non-consensual environments. For B2B streaming and ad-tech stakeholders, this represents a dual threat: wasted media spend and severe brand reputation damage when ads appear tied to intrusive system behavior. As fraudsters leverage system-level triggers that mimic legitimate phone functions, static detection methods are becoming obsolete. The industry should watch for Google to implement stricter 'overlay' permission gates in future Android builds to mitigate these specific system-event hijacks.
Additional Context
The rise of schemes like AfterCall coincides with a broader surge in mobile ecosystem threats. Per Google’s June 2026 security update, Play Protect identified 27 million malicious sideloaded apps in 2025, a 107% increase from the 13 million flagged in 2024. Despite Google’s efforts, which included blocking 1.75 million policy-violating apps from the Play Store in 2025, researchers continue to find sophisticated adware that bypasses initial review. According to Kaspersky, adware accounted for 62% of all Android malware detections in 2025, making it the most prevalent threat by volume for mobile devices.
In response to these evolving tactics, Google is shifting toward a mandatory developer verification model. Per SQ Magazine (August 2025), Google will require all Android developers—including those distributing via third-party stores—to verify their identities by September 2026. This move is designed to create accountability and prevent fraudsters from quickly re-uploading malicious apps under new aliases. Furthermore, DoubleVerify reported in July 2026 that while overall fraud violation rates in North America fell 41% year-over-year, the complexity of AI-driven schemes is rising, with CTV fraud variants growing 140% in early 2026.
Technically, the AfterCall scheme relies on Android 'Intents'—system messages that notify apps of state changes. While Android 17 (released in early 2026) introduced more granular permissions for contacts and location to protect user privacy, the 'ACTION_PHONE_STATE_CHANGED' intent remains a necessary tool for legitimate communication apps. This technical overlap forces verification firms to rely on behavioral AI rather than simple permission blocking to distinguish between a valid caller ID notification and a fraudulent full-screen advertisement.
Read full article at adtechradar.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source