Careful About What App Promotion Ads Recommend! Detecting and Explaining Malware Promotion via App Promotion Graph
Shang Ma (University of Nardam)
Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Malware
Overview
This talk, presented by Shang Ma from the University of Nardam, delves into a critical and often overlooked vector for mobile malware distribution: app promotion ads. While ad-supported apps are ubiquitous and a primary means for users to discover new applications, a significant vulnerability exists within this ecosystem. Specifically, the presentation highlights how "custom-made" app promotion ads, which bypass the vetting processes of established ad libraries, are being actively exploited by malicious actors to promote a wide array of malware. The research underscores the inadequacy of current static analysis methods for detection, proposing a novel, graph-based approach to identify and explain these insidious promotion tactics.
Key moments
- 1:13 App promotion ads exploited to promote malware
- 2:40 Custom-made ads prevalent, risky; static analysis insufficient
- 3:10 Introducing App Promotion Graph for malware detection
- 4:00 Dynamic UI exploration and graph learning methodology
- 5:45 Achieved 97.74% accuracy, promotion relations boost F1
- 6:07 Prevalent malware promotion and sophisticated developer tactics
- 7:30 Temporal analysis reveals new and late-detection malware
- 8:10 In-the-wild case study confirms custom ad malware promotion
Careful About What App Promotion Ads Recommend! Detecting and Explaining Malware Promotion via App Promotion Graph
Speakers: Shang Ma, University of Nardam
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=nQqsI3urcJk
Overview
This talk, presented by Shang Ma from the University of Nardam, delves into a critical and often overlooked vector for mobile malware distribution: app promotion ads. While ad-supported apps are ubiquitous and a primary means for users to discover new applications, a significant vulnerability exists within this ecosystem. Specifically, the presentation highlights how "custom-made" app promotion ads, which bypass the vetting processes of established ad libraries, are being actively exploited by malicious actors to promote a wide array of malware. The research underscores the inadequacy of current static analysis methods for detection, proposing a novel, graph-based approach to identify and explain these insidious promotion tactics.
The talk introduces the concept of an App Promotion Graph, a sophisticated model that maps the relationships between apps through their promotional advertisements. By combining dynamic UI exploration with advanced graph learning techniques, the presented solution aims to automatically detect malware disseminated via these ads. This approach not only identifies malicious apps but also uncovers the intricate promotion chains and strategies employed by attackers, providing crucial insights into the evolving landscape of mobile malware. The findings are particularly relevant for app store operators, ad network providers, and security researchers striving to safeguard the mobile app ecosystem against increasingly sophisticated threats.
The significance of this research lies in addressing a pervasive problem with substantial user impact. With one-third of all users discovering new apps through promotional advertisements, the potential for widespread infection from unvetted custom ads is immense. The talk provides compelling evidence of this risk, demonstrating how current defenses are insufficient and offering a robust, data-driven methodology to combat this specific threat. Its findings extend beyond mere detection, offering a deeper understanding of the adversarial tactics, which is essential for developing more resilient defensive strategies.
Background
▶ Watch: App promotion ads exploited to promote malware (1:13)
The mobile application landscape is heavily reliant on advertising, with app promotion ads serving as a primary discovery mechanism for users. Google research indicates that a substantial one-third of all users find new applications through these advertisements. The standard ecosystem for app promotion involves ad providers creating ads, uploading them to ad libraries like Google AdMob, and app developers integrating these libraries into their applications. Crucially, in this traditional model, the ad content is typically vetted by the ad library, providing a layer of security.
However, a significant loophole exists: app developers can create their own custom-made ads and embed them directly into their applications. These custom ads bypass any third-party vetting process, meaning their content is not scrutinized by ad libraries or other security entities. This lack of oversight creates a fertile ground for exploitation, allowing malicious actors to promote malware without significant impedance. The presentation illustrates this problem with a stark example: a seemingly benign dictionary app that, upon a user attempting to listen to a word's pronunciation, triggers a full-screen ad. This ad falsely claims to have found "236 gigabytes of junk files" and redirects users to Google Play to install a popular "security" app, which, according to user reviews, is actually scamware that aggressively displays ads and lures users into costly, unnecessary subscriptions.
A preliminary study conducted by the researchers on two datasets, Andrew Z and Recall, revealed two critical findings that underscore the severity and complexity of this issue. First, custom-made ads are both prevalent and exceptionally risky. An alarming two-thirds of all ads observed were custom-made, and a staggering 51% of these custom ads promoted malware. This highlights the scale of the unvetted threat vector. Second, the study found that the content of both ad library and custom ads is dynamically requested from servers at runtime. This crucial insight renders traditional static analysis techniques, which examine app code without executing it, largely insufficient for detecting malware promoted by app promotion ads, as the malicious content only manifests during live interaction. The dynamic nature of ad content necessitates a more active, runtime-based detection methodology, setting the stage for the proposed solution.
Key Findings
▶ Watch: Introducing App Promotion Graph for malware detection (3:10)
The research yielded several critical findings that illuminate the scale, nature, and evolution of malware promotion through app promotion ads. First and foremost, the study established the widespread prevalence of malware promotion. Out of the analyzed advertisements, 520 malware promotion ads were identified, constituting 2.64% of all ads. While this percentage might seem small in isolation, the speaker emphasized its significant risk given that one-third of all mobile users discover new apps through such promotions. The types of promoted malware were diverse, including adware, fleeceware, and other malicious categories designed for fraudulent monetization or data exfiltration.
Beyond mere detection, the research uncovered sophisticated promotion tactics exploited by developers. One key finding was the existence of promotion chains, where malware is not directly promoted by benign applications. Instead, it is often disseminated through intermediate applications, termed Potentially Unwanted Apps (PUAs). This multi-stage approach adds complexity to detection efforts, as the direct link between a benign app and a malicious one is obscured. Another tactic observed was the exploitation of flagship apps. Developers would create a high-quality, popular application, upload it to an app store to attract a large user base, and then leverage this legitimate app to promote their less popular, malicious offerings. Furthermore, the study noted the use of non-code ad makers to create a massive volume of adware, effectively "storming" the app market to facilitate malware promotion.
A crucial aspect of the research involved a temporal analysis, comparing findings from February with those six months later in August. This longitudinal study revealed the dynamic nature of the threat. The researchers identified nine "zero apps" in August—completely new malicious applications that had not been observed in February. Worryingly, 18 of these zero apps had already accumulated millions of downloads within that half-year period, underscoring the rapid spread and impact of novel malware. The analysis also uncovered 28 "late detection malware" apps. These applications were considered benign by VirusTotal in February but had evolved into malware by August. Significantly, the proposed graph-based approach was capable of detecting all of these apps as potentially malicious back in February, demonstrating its capability for early detection of evolving threats.
The effectiveness of the proposed approach was quantified through rigorous evaluation. The system achieved an overall accuracy of 97.74% and an F1 score of 95.31% in malware detection. A particularly compelling result was the performance gain achieved by incorporating promotion relations into the detection model; this led to an improvement of 5.17% in F1 scores compared to methods relying solely on app attributes. This demonstrates that understanding the relationships between apps, as captured by the App Promotion Graph, is crucial for robust and accurate malware identification in this context.
Technical Deep Dive
▶ Watch: Achieved 97.74% accuracy, promotion relations boost F1 (5:45)
The core of the presented solution lies in transforming the complex problem of malware detection in app promotion ads into a tractable node classification task within a novel data structure: the App Promotion Graph. This graph conceptually models the relationships where apps (nodes) promote other apps via advertisements (edges). The methodology integrates two primary components: dynamic UI exploration for graph construction and graph learning for malware detection.
The first technical hurdle is collecting the dynamic ad content and constructing the App Promotion Graph. The researchers developed an ad-oriented UI exploration technique designed to accurately identify and extract promotional links. This technique operates in three main phases:
- Deep First Search (DFS) Navigation: The system systematically explores the user interfaces (UIs) of target applications. A Deep First Search strategy is employed to navigate through various screens and functionalities, specifically targeting UIs that are likely to contain advertisements. This ensures a comprehensive sweep of potential ad display locations within an app.
- Ad Content Detection: Once a UI is identified, the system uses empirically crafted text patterns to detect ad content. These patterns are derived from common phrases and keywords found in promotional ads, such as "more apps," "download," "install," and "start now." These linguistic cues help the system distinguish between genuine app content and promotional material.
- Iterative App Restarts for Dynamic Content: Recognizing that ad content is often dynamically requested from servers at runtime, the exploration technique incorporates an iterative restart mechanism. Apps are repeatedly launched and explored to capture the full spectrum of dynamically updated ad content. This ensures that the ephemeral and evolving nature of advertisements does not lead to missed detection opportunities.
Through this meticulous UI exploration, starting from 36,000 seed apps, the researchers successfully constructed an App Promotion Graph comprising 18,000 ads (edges) and 6,000 apps (nodes). This robust dataset forms the foundation for the subsequent malware detection phase.
The second core component is graph learning for malware detection. Existing approaches to mobile malware detection typically rely on app attributes, such as features derived from binary code (e.g., API calls, permissions, manifest analysis). While valuable, these methods treat each app in isolation. The innovation of this research lies in augmenting these traditional attributes with promotion relations extracted directly from the App Promotion Graph.
In this graph learning framework, the task of malware detection is reframed as node classification: each node (app) in the graph is classified as either benign or malicious. The features used for classification are a combination of:
- Traditional App Attributes: These include standard features derived from static and dynamic analysis of the app's binary code, such as permissions requested, sensitive API calls, manifest entries, and code structure.
- Promotion Relations: This is the novel contribution. The graph structure itself provides crucial contextual information. For instance, an app promoted by multiple known malicious apps, or an app that promotes a chain of suspicious applications, would be considered more likely to be malicious. The connections (edges) and their properties (e.g., type of ad, source app, target app) become features in the learning model.
By integrating these promotion relations, the graph learning model can leverage the collective intelligence embedded within the app promotion ecosystem. It can identify patterns of malicious behavior that transcend individual app attributes, such as coordinated promotion campaigns or the use of benign-looking intermediary apps in a promotion chain. The significant performance gain of 5.17% in F1 scores achieved by including these relations unequivocally validates the hypothesis that inter-app relationships are a vital, previously underutilized signal for detecting mobile malware. The graph-based approach moves beyond a siloed view of individual applications, offering a holistic perspective on the adversarial landscape.
Demo / Proof of Concept
▶ Watch: Prevalent malware promotion and sophisticated developer tactics (6:07)
The efficacy and practical applicability of the proposed App Promotion Graph approach were vividly demonstrated through two primary examples: an initial illustrative case of scamware promotion and a more extensive "in-the-wild" case study.
The initial example highlighted the deceptive nature of these ads. A user interacting with a legitimate-looking dictionary app, upon attempting to use a pronunciation feature, was confronted with a full-screen ad. This ad presented a fabricated security alert, claiming the discovery of "236 gigabytes of junk files" on the user's phone. Clicking this enticing, yet false, alert redirected the user to Google Play to download an application. This promoted app, despite having over 100,000 downloads, was identified as scamware through Google reviews. It aggressively displayed advertisements and attempted to trick users into paying for an unnecessary subscription, masquerading as a security cleaner while offering no genuine functionality. This scenario perfectly encapsulates the problem: a seemingly harmless interaction leading to the installation of malicious software, facilitated by an unvetted custom ad.
Building upon this, the researchers conducted a more comprehensive in-the-wild case study to demonstrate the system's ability to uncover real-world malware promotion networks. They initiated the exploration with two specific "parsed video apps" encountered in prior studies, treating them as seed apps. The methodology involved a recursive process: running the seed apps, recording the ads displayed, downloading the apps promoted by those ads, and then running those newly downloaded apps to record their ads, and so forth. This iterative process allowed them to organically construct a segment of the App Promotion Graph as it exists in the wild.
The outcome of this case study was compelling. From these two seed apps, the researchers generated a small but revealing App Promotion Graph consisting of 37 nodes (apps). A striking 21 of these 37 nodes were identified as malware. The types of malware discovered were diverse and predatory, including apps related to gambling, porn, charging scams, and adware. A critical observation from this study was that all of these malicious apps were promoted by custom-made ads, rather than through established ad libraries. This finding strongly reinforces the central premise of the talk: custom ads are the primary vector for this type of malware, precisely because they bypass traditional vetting mechanisms. This in-the-wild demonstration not only validated the detection capabilities of the App Promotion Graph but also underscored its immense potential as a tool for security researchers to actively study and map the intricate, hidden networks of the mobile app underground economy.
Defensive Implications
▶ Watch: In-the-wild case study confirms custom ad malware promotion (8:10)
The findings from this research carry significant implications for various stakeholders within the mobile app ecosystem, necessitating a multi-faceted defensive strategy to counter the pervasive threat of malware promoted via app promotion ads.
For App Store Operators and Ad Libraries (e.g., Google Play, Google AdMob, Facebook Meta Ads, Unity 3D), the primary implication is the urgent need for enhanced and more comprehensive vetting processes. The current reliance on vetting only ads submitted through established libraries is insufficient. App stores must implement mechanisms to scrutinize all ad content, including custom-made ads directly embedded by app developers. This requires moving beyond static code analysis to incorporate dynamic content analysis and runtime monitoring of ads, similar to the UI exploration techniques developed in this research. Detecting dynamically loaded ad content and verifying the legitimacy of the promoted apps are crucial steps. Continuous monitoring for "zero apps" and "late detection malware" is also vital, requiring proactive re-evaluation of app statuses over time.
App Developers also bear a responsibility. While integrating ad functionality, developers should exercise extreme caution, especially when considering custom ad solutions or less reputable ad networks. The risk of inadvertently becoming part of a malware promotion chain, either by promoting malicious apps or by having their own app exploited as a PUA or flagship app, is substantial. Developers should prioritize reputable ad libraries and rigorously audit any custom ad implementations to ensure they are not promoting harmful content. Building trust with users also means ensuring that ads within their apps are not deceptive or disruptive.
Mobile Users are the ultimate target of these malicious campaigns and must adopt a heightened sense of skepticism. The research highlights common social engineering tactics, such as fake security alerts ("clean your phone," "remove trash") and enticing offers. Users should be wary of unexpected full-screen pop-up ads, especially those prompting immediate downloads or subscriptions. Before installing any app, particularly those promoted through ads, users should always check app store reviews, developer reputation, and requested permissions. The presence of aggressive ads or claims of "cleaning" functionality should be red flags.
Finally, for Security Researchers and Analysts, this work introduces a powerful new paradigm. The App Promotion Graph provides a novel framework for understanding and detecting mobile malware that transcends the limitations of isolated app analysis. Future research should leverage graph-based models to uncover more complex adversarial tactics, identify coordinated campaigns, and predict emerging threats. The ability to detect "late detection malware" early, as demonstrated, offers a proactive stance against evolving threats. Further exploration of the underground economy using this graph model can yield deeper insights into attacker motivations, infrastructure, and monetization schemes. The focus must shift towards analyzing the relationships and interactions within the mobile ecosystem, not just the individual components.
Key Takeaways
- Unvetted Custom Ads are a Major Threat: Custom-made app promotion ads, which bypass traditional ad library vetting, are a prevalent and highly risky vector for malware distribution, with 51% of observed custom ads promoting malicious software.
- Malware is Widespread and Deceptive: The research identified 520 malware promotion ads, constituting 2.64% of all ads, promoting diverse malware types like adware and fleeceware, often using social engineering tactics and fake functionalities.
- Sophisticated Promotion Tactics Exist: Attackers utilize complex strategies such as "promotion chains" (using PUAs as intermediaries), exploiting "flagship apps" to promote other malware, and leveraging "non-code ad makers" for mass production of adware.
- Dynamic Analysis and Graph Learning are Essential: Static analysis is insufficient due to dynamic ad content. The novel approach combines dynamic UI exploration to build an App Promotion Graph with graph learning (achieving 97.74% accuracy, 95.31% F1 score) to effectively detect these threats.
- Promotion Relations Enhance Detection: Incorporating the relationships between apps within the App Promotion Graph significantly boosts detection performance, improving the F1 score by 5.17% compared to attribute-only methods.
- Continuous Monitoring is Crucial: The discovery of "zero apps" (new malware with millions of downloads) and "late detection malware" (apps turning malicious over time) underscores the need for ongoing, dynamic surveillance and early detection capabilities in the mobile app ecosystem.
About the Speaker(s)
Shang Ma is a researcher from the University of Nardam. This work was conducted in collaboration with Arizona State University, focusing on innovative methods for detecting and explaining malware promotion within the mobile application ecosystem.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate academic research with a real contribution — using graph-based promotion relationships to catch mobile malware that static analysis misses. The core insight is sound and the detection gains are measurable, but this is squarely a conference paper presentation, not a practitioner-facing talk with operational teeth.
Heather Calloway (CISO) — WEAK
Technically credible research on a real and underappreciated threat vector — custom ad-based malware promotion — but the talk never closes the gap between academic detection methodology and institutional action. The findings are consequential; the delivery leaves the people who could act on them without a clear path forward.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025