In short: Disguise as everyday utilities enables fraudulent Android apps to abuse the SYSTEM_ALERT_WINDOW system permission and deliberately display ads after phone calls.
Fraudsters misuse system permissions on Android devices to display advertisements immediately after phone calls. The DoubleVerify DV Fraud Lab has analyzed and documented this attack method.
The fraudulent apps pose as alarm clocks, calendar or note-taking applications and trick users into granting the extended system permission SYSTEM_ALERT_WINDOW. This permission is essential to display content over other running applications. To convince users to grant it, attackers provide false justifications — such as claiming this permission is necessary for an alarm clock to function correctly when the screen is locked.
Once the permission is granted, the apps monitor phone status via the ACTION_PHONE_STATE_CHANGED command. As soon as the system registers the end of a call, an ad is triggered. These “AfterCall” ads often contain fake call details and conceal advertising content behind them. According to DoubleVerify DV Fraud Lab, they uncover dozens of such apps every month that together are responsible for hundreds of millions of impressions.
To avoid detection and prevent uninstallation, the affected programs automatically remove themselves from the list of recently opened applications. Users who suspect they have infected software should check their Android system’s permission settings. In the System Settings menu under “Special access,” you can see which apps are authorized to display over other applications. Suspicious utility programs can be disabled or completely uninstalled there.
Source: www.it-daily.net · Published 27 July 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.