Reading view

Apple accused of letting fake crypto app steal $1.8 million

Apple’s tagline for its App Store says, “The apps you love. From a place you can trust.” You might love the apps, but can you trust the store? A federal lawsuit filed in the Northern District of California last week suggests not.

Three people have accused Apple of promoting a fake version of the Sparrow Wallet cryptocurrency app through its App Store, even though the real app’s developer had spent over a year telling Apple that he hadn’t produced a version for the mobile platform.

The fake app drained a combined $1.8 million from the victims’ wallets between May and August 2025, and now they’re furious with Apple for allowing it to happen.

How the scam worked

According to the legal complaint published courtesy of BleepingComputer, James Ramirez, Christopher Ellis, and Jalen Delgado downloaded a fake version of Sparrow Wallet from Apple’s App Store. It asked users to enter their recovery phrase (the 12 or 24 words that restore access to a crypto wallet), which is something a legitimate wallet app may also ask for during setup.

Instead of keeping that information private, though, the app handed it to the criminals running the scam. Once someone else has your recovery phrase, they have access to your wallet. If they transfer your cryptocurrency to another address, you cannot get it back.

Ramirez, Ellis, and Delgado say they lost approximately $875,000, $840,000, and $120,000 in Bitcoin, respectively.

Apple terminated the legit developer’s account

The real Sparrow Wallet is a desktop application for Windows, macOS, and Linux. It has never had an official iPhone app.

Craig Raw, the developer of the actual Sparrow Wallet, reported fake versions to Apple in the weeks leading up to January 2024 and publicly confirmed that month that the fake app was still live despite repeated reports.

About a year later, he tried a workaround to stop people from downloading the fake app by submitting a placeholder iOS app with screenshots explicitly warning users that Sparrow Wallet was not available on iOS. Apple responded by terminating his developer account. Thankfully it reversed it later, otherwise he would have been unable to maintain the macOS version.

The complaint also alleges that Apple featured the fake app in curated cryptocurrency collections alongside legitimate products, and allowed additional fake Sparrow Wallet apps onto the App Store even after consumers complained.

Apple’s official response, per TechCrunch, is that:

“apps impersonating others are a violation of its guidelines and it takes swift action to remove them.” Not swift enough, apparently.

The three users are now suing Apple, alleging that it misrepresented the App Store as trustworthy despite knowing about the fake apps. The complaint includes claims of fraudulent concealment, among others, and seeks a jury trial. The plaintiffs are seeking compensation for their losses, along with additional damages permitted under California law.

Not a one-off

Fake cryptocurrency apps are a trend. Kaspersky researchers recently identified 26 crypto wallet impersonators inside Apple’s ecosystem, all targeting seed phrases and recovery keys.

Rather than including malicious code directly inside the app, many of these scams direct users to a convincing fake App Store webpage, where they’re prompted to install another version of the app. That malicious version steals cryptocurrency recovery phrases or private keys by abusing enterprise distribution certificates intended for internal company apps.

How to stay safe

Apple points to its enforcement volume: it terminated 193,000 developer accounts and rejected more than 371,000 copycat submissions in 2025. Those figures come from Apple itself, with no mention of an independent audit. The company says that it uses a mixture of human review and machine learning to spot malicious apps.

If you use cryptocurrency on an iPhone, don’t assume that an App Store listing guarantees an app is genuine. Download apps using links from the developer’s official website whenever possible, and check that the developer actually offers an iPhone version before installing it.

The App Store is generally safer than downloading apps from elsewhere, but this case is a reminder that it is not infallible.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  •  

Apple accused of letting fake crypto app steal $1.8 million

Apple’s tagline for its App Store says, “The apps you love. From a place you can trust.” You might love the apps, but can you trust the store? A federal lawsuit filed in the Northern District of California last week suggests not.

Three people have accused Apple of promoting a fake version of the Sparrow Wallet cryptocurrency app through its App Store, even though the real app’s developer had spent over a year telling Apple that he hadn’t produced a version for the mobile platform.

The fake app drained a combined $1.8 million from the victims’ wallets between May and August 2025, and now they’re furious with Apple for allowing it to happen.

How the scam worked

According to the legal complaint published courtesy of BleepingComputer, James Ramirez, Christopher Ellis, and Jalen Delgado downloaded a fake version of Sparrow Wallet from Apple’s App Store. It asked users to enter their recovery phrase (the 12 or 24 words that restore access to a crypto wallet), which is something a legitimate wallet app may also ask for during setup.

Instead of keeping that information private, though, the app handed it to the criminals running the scam. Once someone else has your recovery phrase, they have access to your wallet. If they transfer your cryptocurrency to another address, you cannot get it back.

Ramirez, Ellis, and Delgado say they lost approximately $875,000, $840,000, and $120,000 in Bitcoin, respectively.

Apple terminated the legit developer’s account

The real Sparrow Wallet is a desktop application for Windows, macOS, and Linux. It has never had an official iPhone app.

Craig Raw, the developer of the actual Sparrow Wallet, reported fake versions to Apple in the weeks leading up to January 2024 and publicly confirmed that month that the fake app was still live despite repeated reports.

About a year later, he tried a workaround to stop people from downloading the fake app by submitting a placeholder iOS app with screenshots explicitly warning users that Sparrow Wallet was not available on iOS. Apple responded by terminating his developer account. Thankfully it reversed it later, otherwise he would have been unable to maintain the macOS version.

The complaint also alleges that Apple featured the fake app in curated cryptocurrency collections alongside legitimate products, and allowed additional fake Sparrow Wallet apps onto the App Store even after consumers complained.

Apple’s official response, per TechCrunch, is that:

“apps impersonating others are a violation of its guidelines and it takes swift action to remove them.” Not swift enough, apparently.

The three users are now suing Apple, alleging that it misrepresented the App Store as trustworthy despite knowing about the fake apps. The complaint includes claims of fraudulent concealment, among others, and seeks a jury trial. The plaintiffs are seeking compensation for their losses, along with additional damages permitted under California law.

Not a one-off

Fake cryptocurrency apps are a trend. Kaspersky researchers recently identified 26 crypto wallet impersonators inside Apple’s ecosystem, all targeting seed phrases and recovery keys.

Rather than including malicious code directly inside the app, many of these scams direct users to a convincing fake App Store webpage, where they’re prompted to install another version of the app. That malicious version steals cryptocurrency recovery phrases or private keys by abusing enterprise distribution certificates intended for internal company apps.

How to stay safe

Apple points to its enforcement volume: it terminated 193,000 developer accounts and rejected more than 371,000 copycat submissions in 2025. Those figures come from Apple itself, with no mention of an independent audit. The company says that it uses a mixture of human review and machine learning to spot malicious apps.

If you use cryptocurrency on an iPhone, don’t assume that an App Store listing guarantees an app is genuine. Download apps using links from the developer’s official website whenever possible, and check that the developer actually offers an iPhone version before installing it.

The App Store is generally safer than downloading apps from elsewhere, but this case is a reminder that it is not infallible.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  •  

AI robocalls: Why caller ID is still lying to you

If you feel like your phone has turned into a scam megaphone, you’re not alone. Robocalls have been a problem for years. Artificial intelligence (AI) is making them slicker, faster, and harder to spot.

A new investigation by Transaction Network Services (TNS) shows that while the big telecom players have stepped up caller ID authentication, many smaller providers are still lagging behind. That leaves plenty of room for criminals to keep making spoofed, AI‑voiced robocalls that seem legitimate right up until they empty your bank account.

Turning back the clock to 2019, lawmakers in the US passed the TRACED Act with a simple goal: make it harder for scammers to lie about who’s calling. The technical was solution STIR/SHAKEN, a pair of catchily-named standards that let phone networks cryptographically sign calls so downstream providers can check whether the caller ID is trustworthy.

On paper, it’s working fairly well for the major carriers. TNS reports that about 85% of voice traffic between Tier 1 networks in 2025 was signed using STIR/SHAKEN, and 93% of those calls received the highest “A” attestation. If the entire ecosystem looked like that, spoofing would become much harder.

Why spoofing still works

The same report found that most lower‑tier communications service providers—typically smaller or specialist carriers—aren’t even close to that level of protection. On average, they only use the required cryptographic signatures about 20% of the time. That means four out of five calls effectively go through the network “unsigned.”

There are reasons for this. The Federal Communications Commission (FCC) has granted some providers extensions, particularly very small and satellite providers, as long as they implement other robocall mitigation measures. Even so, the result is uneven implementation.

From a scammer’s point of view, this is great. Cybercriminals are already using AI to run increasingly sophisticated and scalable robocall attacks and know that even calls with strong authentication can be spoofed or abused when other parts of the chain are weak.

AI voice cloning can be done with just a few seconds of original audio. Combine that with call spoofing and personal information gathered from data breaches, and scammers can make a call appear to come from your bank while using a calm, familiar voice that knows your name or other personal details.

Robocalls cost almost nothing to send. Internet calling allows scammers to dial thousands of numbers for a few cents, which is why the volume is so high. Industry estimates suggest US consumers received around 55 billion robocalls in 2025, with projections creeping toward 60 billion in 2026. That’s roughly 160 million spam calls every single day in one country. Globally, that’s about 385 billion spam/robocall calls each year.

How to stay safe

What can you realistically do as a consumer, given that the network itself is still in transition and attackers are upgrading faster than some carriers?

A few habits still go a long way:

  • Be skeptical of urgency. Real organizations rarely need you to make immediate decisions over the phone about payments, credentials, or remote access. Hang up and call back via a number you find on their official website.
  • Treat caller ID as a clue, not proof. Even if the number looks familiar or matches what you see on a card or website, it can be spoofed.
  • Don’t press buttons or follow instructions in automated menus you didn’t expect. Many robocalls use “press 1 to speak to an agent” as the gateway into a full social‑engineering script.
  • Use call‑blocking and screening tools. Your phone, carrier, or security app may already offer options to block known spam numbers, send unknown callers to voicemail, or label suspicious calls.

And finally—and this is where we can help—check suspicious numbers with our Scam Number Check before you answer or call back.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  •  

AI robocalls: Why caller ID is still lying to you

If you feel like your phone has turned into a scam megaphone, you’re not alone. Robocalls have been a problem for years. Artificial intelligence (AI) is making them slicker, faster, and harder to spot.

A new investigation by Transaction Network Services (TNS) shows that while the big telecom players have stepped up caller ID authentication, many smaller providers are still lagging behind. That leaves plenty of room for criminals to keep making spoofed, AI‑voiced robocalls that seem legitimate right up until they empty your bank account.

Turning back the clock to 2019, lawmakers in the US passed the TRACED Act with a simple goal: make it harder for scammers to lie about who’s calling. The technical was solution STIR/SHAKEN, a pair of catchily-named standards that let phone networks cryptographically sign calls so downstream providers can check whether the caller ID is trustworthy.

On paper, it’s working fairly well for the major carriers. TNS reports that about 85% of voice traffic between Tier 1 networks in 2025 was signed using STIR/SHAKEN, and 93% of those calls received the highest “A” attestation. If the entire ecosystem looked like that, spoofing would become much harder.

Why spoofing still works

The same report found that most lower‑tier communications service providers—typically smaller or specialist carriers—aren’t even close to that level of protection. On average, they only use the required cryptographic signatures about 20% of the time. That means four out of five calls effectively go through the network “unsigned.”

There are reasons for this. The Federal Communications Commission (FCC) has granted some providers extensions, particularly very small and satellite providers, as long as they implement other robocall mitigation measures. Even so, the result is uneven implementation.

From a scammer’s point of view, this is great. Cybercriminals are already using AI to run increasingly sophisticated and scalable robocall attacks and know that even calls with strong authentication can be spoofed or abused when other parts of the chain are weak.

AI voice cloning can be done with just a few seconds of original audio. Combine that with call spoofing and personal information gathered from data breaches, and scammers can make a call appear to come from your bank while using a calm, familiar voice that knows your name or other personal details.

Robocalls cost almost nothing to send. Internet calling allows scammers to dial thousands of numbers for a few cents, which is why the volume is so high. Industry estimates suggest US consumers received around 55 billion robocalls in 2025, with projections creeping toward 60 billion in 2026. That’s roughly 160 million spam calls every single day in one country. Globally, that’s about 385 billion spam/robocall calls each year.

How to stay safe

What can you realistically do as a consumer, given that the network itself is still in transition and attackers are upgrading faster than some carriers?

A few habits still go a long way:

  • Be skeptical of urgency. Real organizations rarely need you to make immediate decisions over the phone about payments, credentials, or remote access. Hang up and call back via a number you find on their official website.
  • Treat caller ID as a clue, not proof. Even if the number looks familiar or matches what you see on a card or website, it can be spoofed.
  • Don’t press buttons or follow instructions in automated menus you didn’t expect. Many robocalls use “press 1 to speak to an agent” as the gateway into a full social‑engineering script.
  • Use call‑blocking and screening tools. Your phone, carrier, or security app may already offer options to block known spam numbers, send unknown callers to voicemail, or label suspicious calls.

And finally—and this is where we can help—check suspicious numbers with our Scam Number Check before you answer or call back.


Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  •  

We rebuilt Malwarebytes Mobile Security for the scams of today 

Nearly half of people encounter a scam on their phone every single day. Malwarebytes is doing something about it.  

That figure comes from a 2025 Malwarebytes survey of 1,300 respondents across the US and Europe. The results paint a troubling picture. A quarter of the victims surveyed reported being harassed or blackmailed, while nearly one in five had private information exposed, and 15% lost money.  

“I felt like I was in a horror movie,” said one survey respondent. “I never thought it would happen to me like this.”  

Your phone is a scammer’s dream. You use it to bank, message, shop, and more. It’s an ideal gateway for anyone looking to take advantage of you. And today’s scams aren’t limited to just one app or program. They show up as texts and delivery notifications, as calls that spoof a trusted number, and as social media DMs. 

Increasingly, AI is making all of this much harder to detect. Malwarebytes research found that half of people feel unprepared for the sophistication of these AI-driven threats. Phone scams now rank among the top five scam types people encounter, according to Malwarebytes Scam Guard data.  

Part of the problem is misplaced trust. According to Malwarebytes’ data, roughly half of people—55% of iPhone owners and 50% of Android owners—said they believe their phone’s security is enough to keep them safe. But relying on those protections alone can leave people vulnerable. 

Malwarebytes detected more than 800,000 distinct strains of Android malware last year and expects that number to cross 1 million in 2026. 

Your phone needs more than just a lock screen to stay safe. That’s why we’ve rebuilt Malwarebytes Mobile Security. It puts scam protection first, and it’s backed by all our other tools to keep your phone secure. 

Built for today’s scams 

Here’s how Malwarebytes Mobile Security helps keep scams away from you and your data. 

Scam Guard is a free AI-powered tool built into Mobile Security for both Android and iOS. Got a suspicious text, email, phone number, link, or message? Drop it into Scam Guard and get an instant read on whether it’s a scam, along with guidance on what to do next.  

Text and Call Protection now catches significantly more junk and scam messages than before. Updated filtering that reviews shortened links more closely and flags suspicious content, like romance-scam language or unexpected money requests, before it reaches your inbox. Call Protection checks every incoming call against known scam and spam numbers, so you can block or flag them automatically instead of gambling on whether to pick up. It’s live now on iOS, with Android rolling out later this summer. 

Malwarebytes Digital Footprint Portal’s free scanner shows you which of your personal details—passwords, Social Security numbers, and more—are already exposed and offers straightforward steps to keep them safe. 

Trusted Advisor gives your device a Protection Score and recommends simple steps to strengthen your security, from adjusting settings and permissions to running a scan or updating your device. 

Expanded ad blocking on iOS now lets you filter Google Sponsored Ads in Safari—a browser that scammers frequently abuse to make fraudulent campaigns look legitimate. 

Android Junk Cleaner removes leftover files, temporary data, and outdated cache files that build up on your device over time. A cleaner, faster phone is easier to manage and gives you the space you need to install important security updates.

  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security

There’s more 

Here’s everything else Mobile Security protects you from: 

Our Malware Scanner (Android) scans for and removes malware and potentially unwanted programs, including screen lockers and adware. 

Real-Time Protection (Android) proactively defends against ransomware, PUPs, and phishing attempts in real time. 

Wi-Fi Monitoring (iOS) warns you when you connect to an insecure network so you can take action by turning on your VPN. 

Malwarebytes Privacy VPN keeps your browsing private with a fast WireGuard connection and a strict no-logs policy supported by diskless, RAM-only server infrastructure. 

Phone scams aren’t going anywhere, but protecting yourself doesn’t have to be complicated. Malwarebytes Mobile Security brings together the tools you need to recognize scams, protect your privacy, and keep your phone safer, all in one app. 

Download Malwarebytes Mobile Security for iOS or Android and use your phone with more confidence. 

  •  

We rebuilt Malwarebytes Mobile Security for the scams of today 

Nearly half of people encounter a scam on their phone every single day. Malwarebytes is doing something about it.  

That figure comes from a 2025 Malwarebytes survey of 1,300 respondents across the US and Europe. The results paint a troubling picture. A quarter of the victims surveyed reported being harassed or blackmailed, while nearly one in five had private information exposed, and 15% lost money.  

“I felt like I was in a horror movie,” said one survey respondent. “I never thought it would happen to me like this.”  

Your phone is a scammer’s dream. You use it to bank, message, shop, and more. It’s an ideal gateway for anyone looking to take advantage of you. And today’s scams aren’t limited to just one app or program. They show up as texts and delivery notifications, as calls that spoof a trusted number, and as social media DMs. 

Increasingly, AI is making all of this much harder to detect. Malwarebytes research found that half of people feel unprepared for the sophistication of these AI-driven threats. Phone scams now rank among the top five scam types people encounter, according to Malwarebytes Scam Guard data.  

Part of the problem is misplaced trust. According to Malwarebytes’ data, roughly half of people—55% of iPhone owners and 50% of Android owners—said they believe their phone’s security is enough to keep them safe. But relying on those protections alone can leave people vulnerable. 

Malwarebytes detected more than 800,000 distinct strains of Android malware last year and expects that number to cross 1 million in 2026. 

Your phone needs more than just a lock screen to stay safe. That’s why we’ve rebuilt Malwarebytes Mobile Security. It puts scam protection first, and it’s backed by all our other tools to keep your phone secure. 

Built for today’s scams 

Here’s how Malwarebytes Mobile Security helps keep scams away from you and your data. 

Scam Guard is a free AI-powered tool built into Mobile Security for both Android and iOS. Got a suspicious text, email, phone number, link, or message? Drop it into Scam Guard and get an instant read on whether it’s a scam, along with guidance on what to do next.  

Text and Call Protection now catches significantly more junk and scam messages than before. Updated filtering that reviews shortened links more closely and flags suspicious content, like romance-scam language or unexpected money requests, before it reaches your inbox. Call Protection checks every incoming call against known scam and spam numbers, so you can block or flag them automatically instead of gambling on whether to pick up. It’s live now on iOS, with Android rolling out later this summer. 

Malwarebytes Digital Footprint Portal’s free scanner shows you which of your personal details—passwords, Social Security numbers, and more—are already exposed and offers straightforward steps to keep them safe. 

Trusted Advisor gives your device a Protection Score and recommends simple steps to strengthen your security, from adjusting settings and permissions to running a scan or updating your device. 

Expanded ad blocking on iOS now lets you filter Google Sponsored Ads in Safari—a browser that scammers frequently abuse to make fraudulent campaigns look legitimate. 

Android Junk Cleaner removes leftover files, temporary data, and outdated cache files that build up on your device over time. A cleaner, faster phone is easier to manage and gives you the space you need to install important security updates.

  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security
  • Malwarebytes Mobile Security

There’s more 

Here’s everything else Mobile Security protects you from: 

Our Malware Scanner (Android) scans for and removes malware and potentially unwanted programs, including screen lockers and adware. 

Real-Time Protection (Android) proactively defends against ransomware, PUPs, and phishing attempts in real time. 

Wi-Fi Monitoring (iOS) warns you when you connect to an insecure network so you can take action by turning on your VPN. 

Malwarebytes Privacy VPN keeps your browsing private with a fast WireGuard connection and a strict no-logs policy supported by diskless, RAM-only server infrastructure. 

Phone scams aren’t going anywhere, but protecting yourself doesn’t have to be complicated. Malwarebytes Mobile Security brings together the tools you need to recognize scams, protect your privacy, and keep your phone safer, all in one app. 

Download Malwarebytes Mobile Security for iOS or Android and use your phone with more confidence. 

  •  

Aftercall ads are driving Android users crazy

Aftercall is a wave of deceptive Android apps on Google Play that pose as everyday tools while bombarding users with pop-up ads after every phone call.

When an unexpected ad pops up every time you hang up a call, it will slowly drive you crazy, especially if you can’t figure out what’s causing it. The ads appear outside the app’s normal context, making it difficult for users to identify and remove the culprit. 

Researchers investigating the campaign discovered a collection of these apps that masquerade as alarm clocks, calendars, and other seemingly harmless apps. After installation, they ask for permission to “appear on top” of other apps. That means they can show a full-screen ad every time you end a call, then hide themselves, making them difficult for users to find and uninstall.

Because the ads appear after you end a call, the researchers dubbed the campaign “Aftercall.”

How the Aftercall scheme works

Think of these apps as fake helpers that piggyback on your phone calls purely to generate ad impressions.

The apps disguise themselves as alarm clocks, calendars, note-taking apps, cleaners, or “super fast” messaging apps and are distributed through the Google Play Store. Researchers found dozens of new apps released every month, collectively responsible for hundreds of millions of ad impressions. 

They trick users into granting overlay permissions. Because Android doesn’t allow this permission to be granted through a standard pop-up, the app has to direct users into Settings, where they must enable it manually. To persuade them, the apps invent plausible reasons. One researcher explained:

“In one example, the alarm app explains that it needs to go off even when the phone is locked – without granting permission, alarms might not appear correctly. Another app, a calendar, doesn’t even leave users a choice – it simply closes, unless they grant the permission.”

Some of these apps also request full-screen notification permissions, allowing them to show ads even when the device is locked.

Aftercall apps monitor the phone’s call state. When it changes from “ringing” to “idle,” indicating that a call has ended, they immediately launch an activity using their overlay permission to pop a screen over everything else and show an ad.

To make the ads seem more legitimate, they wrap them in a fake “call info” screen, complete with caller details, a fake profile picture, and text suggesting the ad relates to the app’s functionality. For the user, this feels like some new post-call feature rather than an unrelated app showing adverts.

They hide to avoid detection and removal. Aftercall apps remove themselves from the “Recent apps” list so when users try the usual “swipe away the suspicious app” approach, they don’t see anything obvious.

How to stay safe

Besides being incredibly annoying for users, the Aftercall campaign also wastes advertisers’ money. After all, would you buy something pushed in this way?

If you see ads pop up right after you end a call, especially alongside fake “call info,” check which apps have the “appear on top” or overlay permissions.

The exact steps vary depending on your phone manufacturer and Android version, but you can usually find them by looking at Settings > Apps > More options (3 vertical dots) > Special access > Appear on top.

Look for apps you don’t recognize, rarely use, or that shouldn’t need overlay access, such as a simple notes app, clock, or cleaner. Disable their “Allow to appear on top” or “Display over other apps” permission. If you’re confident you’ve identified the culprit, uninstall it.

Use an up-to-date, real-time anti-malware app for your device to detect and remove malicious apps.

When installing apps, think carefully before granting permissions. Does the app really need the access it’s asking for to perform its function?

Finally, make sure Google Play Protect is enabled so it can regularly scan apps for known malicious behavior.

  • Open the Google Play Store app on your phone.
  • Tap your profile icon in the top-right corner.
  • Tap Play Protect.
  • Look at the main screen or tap the Settings gear icon to see if Scan apps with Play Protect is turned on.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  •  

Aftercall ads are driving Android users crazy

Aftercall is a wave of deceptive Android apps on Google Play that pose as everyday tools while bombarding users with pop-up ads after every phone call.

When an unexpected ad pops up every time you hang up a call, it will slowly drive you crazy, especially if you can’t figure out what’s causing it. The ads appear outside the app’s normal context, making it difficult for users to identify and remove the culprit. 

Researchers investigating the campaign discovered a collection of these apps that masquerade as alarm clocks, calendars, and other seemingly harmless apps. After installation, they ask for permission to “appear on top” of other apps. That means they can show a full-screen ad every time you end a call, then hide themselves, making them difficult for users to find and uninstall.

Because the ads appear after you end a call, the researchers dubbed the campaign “Aftercall.”

How the Aftercall scheme works

Think of these apps as fake helpers that piggyback on your phone calls purely to generate ad impressions.

The apps disguise themselves as alarm clocks, calendars, note-taking apps, cleaners, or “super fast” messaging apps and are distributed through the Google Play Store. Researchers found dozens of new apps released every month, collectively responsible for hundreds of millions of ad impressions. 

They trick users into granting overlay permissions. Because Android doesn’t allow this permission to be granted through a standard pop-up, the app has to direct users into Settings, where they must enable it manually. To persuade them, the apps invent plausible reasons. One researcher explained:

“In one example, the alarm app explains that it needs to go off even when the phone is locked – without granting permission, alarms might not appear correctly. Another app, a calendar, doesn’t even leave users a choice – it simply closes, unless they grant the permission.”

Some of these apps also request full-screen notification permissions, allowing them to show ads even when the device is locked.

Aftercall apps monitor the phone’s call state. When it changes from “ringing” to “idle,” indicating that a call has ended, they immediately launch an activity using their overlay permission to pop a screen over everything else and show an ad.

To make the ads seem more legitimate, they wrap them in a fake “call info” screen, complete with caller details, a fake profile picture, and text suggesting the ad relates to the app’s functionality. For the user, this feels like some new post-call feature rather than an unrelated app showing adverts.

They hide to avoid detection and removal. Aftercall apps remove themselves from the “Recent apps” list so when users try the usual “swipe away the suspicious app” approach, they don’t see anything obvious.

How to stay safe

Besides being incredibly annoying for users, the Aftercall campaign also wastes advertisers’ money. After all, would you buy something pushed in this way?

If you see ads pop up right after you end a call, especially alongside fake “call info,” check which apps have the “appear on top” or overlay permissions.

The exact steps vary depending on your phone manufacturer and Android version, but you can usually find them by looking at Settings > Apps > More options (3 vertical dots) > Special access > Appear on top.

Look for apps you don’t recognize, rarely use, or that shouldn’t need overlay access, such as a simple notes app, clock, or cleaner. Disable their “Allow to appear on top” or “Display over other apps” permission. If you’re confident you’ve identified the culprit, uninstall it.

Use an up-to-date, real-time anti-malware app for your device to detect and remove malicious apps.

When installing apps, think carefully before granting permissions. Does the app really need the access it’s asking for to perform its function?

Finally, make sure Google Play Protect is enabled so it can regularly scan apps for known malicious behavior.

  • Open the Google Play Store app on your phone.
  • Tap your profile icon in the top-right corner.
  • Tap Play Protect.
  • Look at the main screen or tap the Settings gear icon to see if Scan apps with Play Protect is turned on.

Scammers know more about you than you think. 

Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. 

Download for iOS → Download for Android → 

  •  
❌