TY - JOUR
T1 - The arts and crafts of android adware across a decade
AU - Wang, Chao
AU - Liu, Tianming
AU - Zhao, Yanjie
AU - Zhang, Lin
AU - Du, Xiaoning
AU - Li, Li
AU - Wang, Haoyu
N1 - Publisher Copyright:
© The Author(s), under exclusive licence to Springer Science+Business Media, LLC, part of Springer Nature 2025.
PY - 2026/6
Y1 - 2026/6
N2 - Adware represents a pervasive threat in the mobile ecosystem, yet its inherent characteristics have been largely overlooked by previous research. This work takes a crucial step towards demystifying Android adware. We present AdwareZoo, a comprehensive dataset comprising 15,996 adware samples across 118 distinct families collected from security reports and app repositories. We identify adware family payloads by isolating packages from samples for VirusTotal rescanning, unveiling distinctive patterns in family naming conventions, and exposing the misclassification of legitimate ad networks as adware. Our analysis of payload location strategies reveals that over 30% of adware families employ payloads beyond conventional Java/Kotlin code. Based on our dataset analysis, we conducted a comprehensive Adware Characterization of 92 distinct adware families, revealing diverse implementation patterns and evolving techniques across the mobile ecosystem. To facilitate this analysis, we developed an Adware Characterization Schema that provided a structured taxonomy for systematically classifying the observed behaviors. Our investigation uncovered multiple categories of fraudulent activities, including aggressive ad display techniques, sophisticated click fraud implementations, privacy information leakage, malicious promotion mechanisms, and various persistence and evasion mechanisms employed to avoid detection while maximizing illicit revenue. This research establishes foundations for comprehending the fraudulent and adversarial techniques within the mobile adware landscape and facilitates the development of more robust detection mechanisms against these evolving threats.
AB - Adware represents a pervasive threat in the mobile ecosystem, yet its inherent characteristics have been largely overlooked by previous research. This work takes a crucial step towards demystifying Android adware. We present AdwareZoo, a comprehensive dataset comprising 15,996 adware samples across 118 distinct families collected from security reports and app repositories. We identify adware family payloads by isolating packages from samples for VirusTotal rescanning, unveiling distinctive patterns in family naming conventions, and exposing the misclassification of legitimate ad networks as adware. Our analysis of payload location strategies reveals that over 30% of adware families employ payloads beyond conventional Java/Kotlin code. Based on our dataset analysis, we conducted a comprehensive Adware Characterization of 92 distinct adware families, revealing diverse implementation patterns and evolving techniques across the mobile ecosystem. To facilitate this analysis, we developed an Adware Characterization Schema that provided a structured taxonomy for systematically classifying the observed behaviors. Our investigation uncovered multiple categories of fraudulent activities, including aggressive ad display techniques, sophisticated click fraud implementations, privacy information leakage, malicious promotion mechanisms, and various persistence and evasion mechanisms employed to avoid detection while maximizing illicit revenue. This research establishes foundations for comprehending the fraudulent and adversarial techniques within the mobile adware landscape and facilitates the development of more robust detection mechanisms against these evolving threats.
KW - Android adware
KW - Android malware dataset
KW - Malware characterization
KW - Mobile advertising
UR - https://www.scopus.com/pages/publications/105021473303
U2 - 10.1007/s10515-025-00575-9
DO - 10.1007/s10515-025-00575-9
M3 - 文章
AN - SCOPUS:105021473303
SN - 0928-8910
VL - 33
JO - Automated Software Engineering
JF - Automated Software Engineering
IS - 1
M1 - 30
ER -