Android “Aftercall” Apps Push Ads After Every Call

Malwarebytes · Medium sophistication
Last updated July 27, 2026

Researchers found a campaign of deceptive Android apps on Google Play that pretend to be helpful tools (alarms, calendars, cleaners) but show full-screen ads right after a phone call ends. The apps persuade users to grant special “appear on top” (overlay) permissions so the ads can pop up over anything, then they hide to make removal harder.

Key findings

  • Deceptive apps on Google Play masquerade as common utilities (alarm clocks, calendars, note-taking, cleaners, messaging) but display ads after calls end.
  • They socially engineer users into enabling Android overlay (“appear on top”) permissions by giving plausible-sounding reasons or blocking app use unless granted.
  • After a call ends (call state changes to idle), the apps immediately display a full-screen ad over other apps, sometimes even on the lock screen (via full-screen notification permissions).
  • To appear legitimate, ads are wrapped in a fake “call info” interface with caller details and a fake profile picture.
  • The apps attempt to evade discovery by removing themselves from the “Recent apps” list, making them harder to identify and uninstall.

Who’s being targeted

  • Commonly targeted roles: All employees (Android users), BYOD users, Mobile/Endpoint support teams, Security awareness training audience.
  • Affected industries: All (Android users/consumers, including employees using personal or work Android devices).
  • Attack channels: website.
  • Impersonated: A legitimate-looking utility app (e.g., alarm clock or calendar), A phone/call feature UI (fake ‘call info’ screen).

Awareness takeaways

  • Treat ‘Display over other apps’ / overlay permission as high-risk; only grant it to apps that truly need it.
  • If ads appear right after calls end, review which apps have overlay access and remove unnecessary ones.
  • Be suspicious of apps that block functionality unless you grant a powerful permission.
  • Keep Google Play Protect enabled and consider reputable mobile security to detect malicious apps.

Red flags to watch for

  • An app requests overlay/‘appear on top’ permission even though it’s a simple tool (notes/clock/cleaner)
  • The app forces the decision (closes or won’t work unless permission is granted)
  • The rationale feels unrelated to the core feature (permission is broader than necessary)
  • Full-screen ads appear immediately after ending calls, outside any app you opened
  • The screen looks like a phone feature you didn’t enable or install
  • You can’t find the responsible app in ‘Recent apps’
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Ever hang up a call and suddenly a full‑screen ad appears, like some weird ‘call info’ screen? That’s the ‘Aftercall’ trick: shady Android apps on Google Play posing as alarm clocks or calendars, then pushing you to enable ‘Display over other apps’ so they can pop ads over everything the moment a call ends. They even fake a ‘call info’ layout with caller details and a profile picture to make the ad feel legit, then hide from the Recent apps list so you can’t tell which so-called alarm or calendar is doing it. If you see ads right after calls, don’t ignore it, open Android Settings, check who has ‘Display over other apps’ permission, and strip it from anything that doesn’t truly need it.

Similar attacks

Encrypted Prompt Injection Tricks AI Tools

Encrypted Prompt Injection Tricks AI Tools

Researchers demonstrated a prompt-injection method that hides malicious instructions inside encrypted text, then tricks an AI assistant into decrypting it using built-in code tools. In tests, a normal “summarize this page” request could cause Grok to exfiltrate chat data without any click or…

August 25, 2026
Fake Verification Pages Push PavinLoader Malware

Fake Verification Pages Push PavinLoader Malware

Malwarebytes reports that a multi-stage Windows malware loader called PavinLoader is being delivered through multiple real-world campaigns, including ClickFix “verification” pages and fake software downloads. Victims are tricked into running installers or scripts that use legitimate Windows tools…

August 24, 2026
Phishers Hijack Meta/Google Ad Accounts for Profit

Phishers Hijack Meta/Google Ad Accounts for Profit

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google Workspace mail-merge, and SharePoint links. The stolen accounts are valuable not just for the budget inside them, but because older accounts with…

July 29, 2026
One-Click Sogou Link Trick Dropped GRAYRABBIT

One-Click Sogou Link Trick Dropped GRAYRABBIT

Researchers reported a real intrusion where a China-linked group used a crafted link to exploit Sogou Input Method on Windows and install the GRAYRABBIT backdoor. Victims were lured into opening a special link (potentially via email or chat), which redirected Sogou’s built-in browser to an…

September 11, 2026
China-Linked Hackers Push “Gemini” Phish With Zero-Days

China-Linked Hackers Push “Gemini” Phish With Zero-Days

Proofpoint reports multiple China-aligned espionage groups used a chained set of browser/Windows zero-days (“BlueMoon”) and delivered it through phishing emails. Victims who clicked a phishing link could end up with a malicious browser extension disguised as Google Gemini, letting attackers watch…

September 11, 2026
BlueMoon Spearphish Turns One Click Into Admin

BlueMoon Spearphish Turns One Click Into Admin

Proofpoint reports that multiple espionage-focused groups are using a shared “BlueMoon” toolkit to run targeted spear‑phishing campaigns that trick people into clicking a link. A single click can trigger a Chrome/Windows exploit chain that gives attackers full Windows admin access and lets them…

September 11, 2026