Android “Aftercall” Apps Push Ads After Every Call

Malwarebytes · Medium sophistication
Last updated July 27, 2026

Researchers found a campaign of deceptive Android apps on Google Play that pretend to be helpful tools (alarms, calendars, cleaners) but show full-screen ads right after a phone call ends. The apps persuade users to grant special “appear on top” (overlay) permissions so the ads can pop up over anything, then they hide to make removal harder.

Key findings

  • Deceptive apps on Google Play masquerade as common utilities (alarm clocks, calendars, note-taking, cleaners, messaging) but display ads after calls end.
  • They socially engineer users into enabling Android overlay (“appear on top”) permissions by giving plausible-sounding reasons or blocking app use unless granted.
  • After a call ends (call state changes to idle), the apps immediately display a full-screen ad over other apps, sometimes even on the lock screen (via full-screen notification permissions).
  • To appear legitimate, ads are wrapped in a fake “call info” interface with caller details and a fake profile picture.
  • The apps attempt to evade discovery by removing themselves from the “Recent apps” list, making them harder to identify and uninstall.

Who’s being targeted

  • Commonly targeted roles: All employees (Android users), BYOD users, Mobile/Endpoint support teams, Security awareness training audience.
  • Affected industries: All (Android users/consumers, including employees using personal or work Android devices).
  • Attack channels: website.
  • Impersonated: A legitimate-looking utility app (e.g., alarm clock or calendar), A phone/call feature UI (fake ‘call info’ screen).

Awareness takeaways

  • Treat ‘Display over other apps’ / overlay permission as high-risk; only grant it to apps that truly need it.
  • If ads appear right after calls end, review which apps have overlay access and remove unnecessary ones.
  • Be suspicious of apps that block functionality unless you grant a powerful permission.
  • Keep Google Play Protect enabled and consider reputable mobile security to detect malicious apps.

Red flags to watch for

  • An app requests overlay/‘appear on top’ permission even though it’s a simple tool (notes/clock/cleaner)
  • The app forces the decision (closes or won’t work unless permission is granted)
  • The rationale feels unrelated to the core feature (permission is broader than necessary)
  • Full-screen ads appear immediately after ending calls, outside any app you opened
  • The screen looks like a phone feature you didn’t enable or install
  • You can’t find the responsible app in ‘Recent apps’
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Ever hang up a call and suddenly a full‑screen ad appears, like some weird ‘call info’ screen? That’s the ‘Aftercall’ trick: shady Android apps on Google Play posing as alarm clocks or calendars, then pushing you to enable ‘Display over other apps’ so they can pop ads over everything the moment a call ends. They even fake a ‘call info’ layout with caller details and a profile picture to make the ad feel legit, then hide from the Recent apps list so you can’t tell which so-called alarm or calendar is doing it. If you see ads right after calls, don’t ignore it, open Android Settings, check who has ‘Display over other apps’ permission, and strip it from anything that doesn’t truly need it.

Similar attacks

LogoKit Builds Real-Time Fake Login Pages

LogoKit Builds Real-Time Fake Login Pages

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

July 29, 2026