Skip to main navigation Skip to search Skip to main content

The arts and crafts of android adware across a decade

  • Chao Wang
  • , Tianming Liu
  • , Yanjie Zhao
  • , Lin Zhang
  • , Xiaoning Du
  • , Li Li
  • , Haoyu Wang*
  • *Corresponding author for this work
  • Huazhong University of Science and Technology
  • The National Computer Emergency Response Team/Coordination Center of China (CNCERT/CC)
  • Monash University

Research output: Contribution to journalArticlepeer-review

Abstract

Adware represents a pervasive threat in the mobile ecosystem, yet its inherent characteristics have been largely overlooked by previous research. This work takes a crucial step towards demystifying Android adware. We present AdwareZoo, a comprehensive dataset comprising 15,996 adware samples across 118 distinct families collected from security reports and app repositories. We identify adware family payloads by isolating packages from samples for VirusTotal rescanning, unveiling distinctive patterns in family naming conventions, and exposing the misclassification of legitimate ad networks as adware. Our analysis of payload location strategies reveals that over 30% of adware families employ payloads beyond conventional Java/Kotlin code. Based on our dataset analysis, we conducted a comprehensive Adware Characterization of 92 distinct adware families, revealing diverse implementation patterns and evolving techniques across the mobile ecosystem. To facilitate this analysis, we developed an Adware Characterization Schema that provided a structured taxonomy for systematically classifying the observed behaviors. Our investigation uncovered multiple categories of fraudulent activities, including aggressive ad display techniques, sophisticated click fraud implementations, privacy information leakage, malicious promotion mechanisms, and various persistence and evasion mechanisms employed to avoid detection while maximizing illicit revenue. This research establishes foundations for comprehending the fraudulent and adversarial techniques within the mobile adware landscape and facilitates the development of more robust detection mechanisms against these evolving threats.

Original languageEnglish
Article number30
JournalAutomated Software Engineering
Volume33
Issue number1
DOIs
StatePublished - Jun 2026

Keywords

  • Android adware
  • Android malware dataset
  • Malware characterization
  • Mobile advertising

Fingerprint

Dive into the research topics of 'The arts and crafts of android adware across a decade'. Together they form a unique fingerprint.

Cite this