Threat reportMalwareTL-2026-1724

Aftercall: Android Adware Campaign Abuses Overlay/Full-Screen Permissions to Bombard Users with Post-Call Ads

mediumACTIVE

Aftercall: Android Adware Campaign Abuses (TL-2026-1724), also tracked as AfterCall, is a medium-severity malware campaign, first published 2026-07-27. It has no confirmed attribution, affects Google Android (apps distributed via the Google Play Store), maps to 5 MITRE ATT&CK techniques (T1624, T1628, T1629), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-1724

Threat ID
TL-2026-1724
Also known as
AfterCall, AfterCall Ads
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, advertising, mobiletechnology
Target regions
Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in Aftercall: Android Adware Campaign Abuses

Malware and tooling: AfterCall / Aftercall Ads (Android overlay ad-fraud/adware technique family)

How Aftercall: Android Adware Campaign Abuses works

DoubleVerify's Fraud Lab disclosed "AfterCall," a large-scale Android ad-fraud technique in which apps disguised as alarm clocks, calendars, notes tools, cleaners, and messaging apps monitor phone call state and fire a full-screen ad the instant a call ends. The apps abuse the SYSTEM_ALERT_WINDOW ("Display over other apps") and USE_FULL_SCREEN_INTENT permissions and remove themselves from the Recent Apps list to resist identification and uninstall; dozens of new apps are published on Google Play each month, collectively generating hundreds of millions of ad impressions, and at least one instance remained live on Google Play with over 100,000 installs as of late-July 2026 reporting.

AfterCall (also written "Aftercall") is an Android ad-fraud/adware technique first publicly documented by DoubleVerify's Fraud Lab (DV Engineering) on 13 July 2026 and subsequently covered by The Hacker News' ThreatsDay Bulletin (23 July 2026), Cybernews and the Spanish-language ad-tech trade outlet IPMark (both 24 July 2026), and Malwarebytes Labs (27 July 2026, author Pieter Arntz) -- the source article that triggered this hunt.

The apps are distributed through the official Google Play Store disguised as everyday utilities -- alarm clocks, calendars, notes apps -- and, per Malwarebytes' review, also as cleaner/optimizer and messaging apps. Unlike normal Android permissions, they deceptively obtain the SYSTEM_ALERT_WINDOW ("Display over other apps"/"Appear on top") special permission. Because this permission cannot be granted through a standard in-app dialog, the app redirects the user into the Settings app and supplies a false justification for why it is needed (e.g., an alarm app claiming the permission is required for alarms to fire while the device is locked); IPMark notes less technically-savvy users are more likely to approve the redirect without understanding the implication. Some apps additionally request the USE_FULL_SCREEN_INTENT permission, which lets a notification render as a full-screen activity even over the lock screen.

Once granted, the app registers a manifest BroadcastReceiver for the PHONE_STATE / ACTION_PHONE_STATE_CHANGED system broadcast, set to an unusually high priority (998) so it runs ahead of other apps (such as legitimate caller-ID tools) listening for the same event. The receiver watches for the call-state transition from RINGING to IDLE -- the moment a call ends -- and immediately launches a full-screen overlay Activity displaying an advertisement, functioning even when the serving app is not actively in use. To increase apparent legitimacy, the ad is wrapped in a fake "call info" screen showing caller details and a profile picture, mimicking a native post-call summary. The same apps also register for device-startup, app-update, and power-connection broadcasts to help the ad-serving mechanism survive reboots and updates.

To resist user-driven removal, the ad-displaying Activity is configured (via manifest attributes such as excludeFromRecents) to omit itself from the Android "Recent Apps"/Overview screen, so a user who swipes away the offending screen cannot easily trace it back to the installed app responsible -- Malwarebytes and The Hacker News both describe this explicitly as evading "identification and manual removal." DoubleVerify notes detection is difficult precisely because the apps do not share package names or identical code structure, and because legitimate caller-ID/utility apps can produce superficially similar post-call behavior, limiting the effectiveness of both static (package/signature) and simple behavioral detection; IPMark's coverage characterizes DV Fraud Lab's countermeasure as AI-driven analysis of behavioral variants across the app population rather than signature matching. Cybernews' 24 July 2026 report additionally found that, despite DoubleVerify's prior disclosure, some AfterCall-pattern apps remained available for download on Google Play at time of writing, including at least one with over 100,000 installs -- indicating the technique's replication rate was still outpacing platform-side takedown as of that date.

DoubleVerify's Fraud Lab states it uncovers dozens of new apps implementing this technique every month, and assesses the scheme as collectively responsible for hundreds of millions of fraudulent/low-quality ad impressions, harming advertisers (wasted spend, unwanted brand association with intrusive behavior) and users (unwanted, difficult-to-remove ad bombardment) alike. No CVE applies -- this is a permission-abuse/ad-fraud technique rather than a software vulnerability -- and no specific package names, C2 infrastructure, or file hashes were disclosed by any source reviewed, consistent with the technique being a UX/permission-abuse pattern replicated across many independently-built apps rather than a single piece of malware with fixed indicators.

Platform-side mitigation: per Android's own developer documentation (source.android.com/docs/core/permissions/fsi-limits), Android 14+ restricts the default grant of USE_FULL_SCREEN_INTENT to apps that declare calling or alarm functionality, and Google Play auto-revokes the permission at install time for apps outside those categories; devices running Android 13 or earlier retain the prior default grant. The SYSTEM_ALERT_WINDOW overlay permission itself still requires only a manual Settings grant regardless of Android version or app category, so this control narrows but does not close the AfterCall vector.

MITRE ATT&CK Mobile scope: this is a narrow, single-technique-family ad-fraud campaign rather than a multi-stage intrusion -- no exploit, no C2, no credential access, no data collection, no lateral movement, and no privilege escalation are described by any source. Cross-checked against the full current Mobile ATT&CK matrix (12 tactics, ~90 techniques/sub-techniques), the sourced behavior supports exactly five techniques across three tactics: Persistence (Event Triggered Execution: Broadcast Receivers, T1624.001, for the high-priority PHONE_STATE receiver); three Defense Evasion techniques (Masquerading: Match Legitimate Name or Location, T1655.001, for the utility-app disguise; Hide Artifacts: User Evasion, T1628.002, for the Recent-Apps exclusion; Impair Defenses: Prevent Application Removal, T1629.001, for the resulting identification/removal resistance); and Impact (Generate Traffic from Victim, T1643, for the fraudulent ad-impression generation). Candidate techniques explicitly ruled out for lacking sourced support include System Information Discovery (T1426) and Access Notifications (T1517) -- phone-state monitoring here is purely an execution trigger, not reconnaissance or notification interception -- Lockscreen Bypass (T1461) -- USE_FULL_SCREEN_INTENT is an OS-sanctioned notification capability, not a defeat of lock authentication -- Boot or Logon Initialization Scripts (T1398) and Foreground Persistence (T1541) -- only manifest broadcast receivers are described, not root-level boot scripts or foreground-service abuse -- and any Command and Control, Credential Access, or Collection technique, since ad-serving traffic is ordinary ad-network communication and no source describes data collection beyond the call-state signal used to fire the ad. A separate DoubleVerify report on a 'zombie'-developer-account Android ad-fraud scheme (compromised dormant accounts driving bot-based click fraud on gaming apps) was reviewed and confirmed unrelated to AfterCall -- no shared mechanism, apps, or actors -- and is excluded from this record.

MITRE ATT&CK techniques used in TL-2026-1724

Persistence

T1624 Event Triggered Execution

Defense Evasion

T1628 Hide Artifacts; T1629 Impair Defenses; T1655 Masquerading

Impact

T1643 Generate Traffic from Victim

Affected products and versions in Aftercall: Android Adware Campaign Abuses

  • Google — Android (apps distributed via the Google Play Store)
    Vulnerable versions: Any Android release supporting the SYSTEM_ALERT_WINDOW and USE_FULL_SCREEN_INTENT permissions

Remediation for Aftercall: Android Adware Campaign Abuses

Immediate actions

  • Audit installed apps' "Display over other apps" (SYSTEM_ALERT_WINDOW) grants via Settings > Apps > Special access/More options > Appear on top, and revoke the permission for any utility app (alarm/calendar/notes/cleaner/messaging) that does not clearly need it
  • Uninstall alarm-clock, calendar, notes, cleaner, or messaging apps that request overlay or full-screen-intent permissions without an obvious functional reason, especially ones that cannot be found in Recent Apps after showing a full-screen ad
  • Enable Google Play Protect scanning and keep it active, per Malwarebytes' consumer guidance
  • Advertisers and ad networks should apply DoubleVerify (or an equivalent ad-verification vendor's) pre-bid and post-bid invalid-traffic filtering to exclude AfterCall-pattern inventory

Workarounds

  • Disable the "Display over other apps"/"Appear on top" permission per-app in Android Settings
  • Disable "Allow full-screen notifications"/lock-screen full-screen intent access per-app where the OS exposes that toggle

Longer-term hardening

  • Google Play review/runtime enforcement should more tightly gate SYSTEM_ALERT_WINDOW and USE_FULL_SCREEN_INTENT grants for utility-category apps, particularly where the app also excludes its activities from Recent Apps
  • Advertisers should require ad-verification/invalid-traffic coverage from vendors such as DoubleVerify across all mobile inventory, not just premium placements
  • Mobile threat defense (MTD) / enterprise MDM tooling should flag and alert on apps that combine an overlay/full-screen-intent permission grant with Recent-Apps self-exclusion, since that specific combination is the AfterCall fingerprint
  • Given Cybernews' finding that AfterCall-pattern apps continued to be published/remain live after DoubleVerify's disclosure, ad-verification and app-store trust-and-safety teams should treat detection as an ongoing, recurring sweep rather than a one-time takedown

Timeline of Aftercall: Android Adware Campaign Abuses

  • In the same disclosure, DoubleVerify states its Fraud Lab uncovers dozens of new AfterCall-pattern apps every month on Google Play, collectively responsible for hundreds of millions of ad impressions.
  • DoubleVerify's Fraud Lab (DV Engineering) publishes "A New Ad Fraud Trend: AfterCall Ads" on Medium, the first public disclosure of the technique, naming it and detailing the permission/broadcast mechanism.
  • The Hacker News includes the AfterCall campaign as an entry in its ThreatsDay Bulletin roundup, noting the apps "use evasion techniques that make them difficult for users to identify and uninstall," amplifying DoubleVerify's findings to a broader infosec audience.
  • IPMark, a Spanish-language advertising/marketing trade outlet, publishes coverage citing DoubleVerify's findings and characterizing DV Fraud Lab's detection approach as AI-based analysis of behavioral variants across the app population rather than static package/signature matching.
  • Cybernews additionally reports that, despite DoubleVerify's prior disclosure, some AfterCall-pattern apps remained available for download on Google Play at time of writing, including at least one app with over 100,000 installs.
  • Cybernews publishes independent coverage of the AfterCall technique, confirming the SYSTEM_ALERT_WINDOW/USE_FULL_SCREEN_INTENT permission-abuse and ACTION_PHONE_STATE_CHANGED broadcast mechanism and citing DoubleVerify's findings.
  • Malwarebytes' coverage publishes specific consumer remediation steps (Settings > Apps > Special access > Appear on top; enable Google Play Protect scanning) for identifying and revoking overlay permissions from suspect utility apps.
  • Malwarebytes Labs (author Pieter Arntz) publishes "Aftercall ads are driving Android users crazy," syndicating DoubleVerify's findings to a consumer-facing security audience; this is the article that triggered this TL-Intel Harness entry.

Sources cited for Aftercall: Android Adware Campaign Abuses

Detection coverage for TL-2026-1724

As of 2026-07-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1724 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats