Abstract
Adware represents a pervasive threat in the mobile ecosystem, yet its inherent characteristics have been largely overlooked by previous research. This work takes a crucial step towards demystifying Android adware. We present AdwareZoo, a comprehensive dataset comprising 15,996 adware samples across 118 distinct families collected from security reports and app repositories. We identify adware family payloads by isolating packages from samples for VirusTotal rescanning, unveiling distinctive patterns in family naming conventions, and exposing the misclassification of legitimate ad networks as adware. Our analysis of payload location strategies reveals that over 30% of adware families employ payloads beyond conventional Java/Kotlin code. Based on our dataset analysis, we conducted a comprehensive Adware Characterization of 92 distinct adware families, revealing diverse implementation patterns and evolving techniques across the mobile ecosystem. To facilitate this analysis, we developed an Adware Characterization Schema that provided a structured taxonomy for systematically classifying the observed behaviors. Our investigation uncovered multiple categories of fraudulent activities, including aggressive ad display techniques, sophisticated click fraud implementations, privacy information leakage, malicious promotion mechanisms, and various persistence and evasion mechanisms employed to avoid detection while maximizing illicit revenue. This research establishes foundations for comprehending the fraudulent and adversarial techniques within the mobile adware landscape and facilitates the development of more robust detection mechanisms against these evolving threats.
| Original language | English |
|---|---|
| Article number | 30 |
| Journal | Automated Software Engineering |
| Volume | 33 |
| Issue number | 1 |
| DOIs | |
| State | Published - Jun 2026 |
Keywords
- Android adware
- Android malware dataset
- Malware characterization
- Mobile advertising
Fingerprint
Dive into the research topics of 'The arts and crafts of android adware across a decade'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver