Android “Aftercall” Apps Push Ads After Every Call

Malwarebytes · Medium sophistication
Last updated July 27, 2026

Researchers found a campaign of deceptive Android apps on Google Play that pretend to be helpful tools (alarms, calendars, cleaners) but show full-screen ads right after a phone call ends. The apps persuade users to grant special “appear on top” (overlay) permissions so the ads can pop up over anything, then they hide to make removal harder.

Key findings

  • Deceptive apps on Google Play masquerade as common utilities (alarm clocks, calendars, note-taking, cleaners, messaging) but display ads after calls end.
  • They socially engineer users into enabling Android overlay (“appear on top”) permissions by giving plausible-sounding reasons or blocking app use unless granted.
  • After a call ends (call state changes to idle), the apps immediately display a full-screen ad over other apps, sometimes even on the lock screen (via full-screen notification permissions).
  • To appear legitimate, ads are wrapped in a fake “call info” interface with caller details and a fake profile picture.
  • The apps attempt to evade discovery by removing themselves from the “Recent apps” list, making them harder to identify and uninstall.

Who’s being targeted

  • Commonly targeted roles: All employees (Android users), BYOD users, Mobile/Endpoint support teams, Security awareness training audience.
  • Affected industries: All (Android users/consumers, including employees using personal or work Android devices).
  • Attack channels: website.
  • Impersonated: A legitimate-looking utility app (e.g., alarm clock or calendar), A phone/call feature UI (fake ‘call info’ screen).

Awareness takeaways

  • Treat ‘Display over other apps’ / overlay permission as high-risk; only grant it to apps that truly need it.
  • If ads appear right after calls end, review which apps have overlay access and remove unnecessary ones.
  • Be suspicious of apps that block functionality unless you grant a powerful permission.
  • Keep Google Play Protect enabled and consider reputable mobile security to detect malicious apps.

Red flags to watch for

  • An app requests overlay/‘appear on top’ permission even though it’s a simple tool (notes/clock/cleaner)
  • The app forces the decision (closes or won’t work unless permission is granted)
  • The rationale feels unrelated to the core feature (permission is broader than necessary)
  • Full-screen ads appear immediately after ending calls, outside any app you opened
  • The screen looks like a phone feature you didn’t enable or install
  • You can’t find the responsible app in ‘Recent apps’
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Ever hang up a call and suddenly a full‑screen ad appears, like some weird ‘call info’ screen? That’s the ‘Aftercall’ trick: shady Android apps on Google Play posing as alarm clocks or calendars, then pushing you to enable ‘Display over other apps’ so they can pop ads over everything the moment a call ends. They even fake a ‘call info’ layout with caller details and a profile picture to make the ad feel legit, then hide from the Recent apps list so you can’t tell which so-called alarm or calendar is doing it. If you see ads right after calls, don’t ignore it, open Android Settings, check who has ‘Display over other apps’ permission, and strip it from anything that doesn’t truly need it.

Similar attacks

Phishers Hijack Meta/Google Ad Accounts for Profit

Phishers Hijack Meta/Google Ad Accounts for Profit

Criminal groups are stealing Meta Business Manager and Google Ads accounts using phishing that arrives through trusted platforms like Salesforce, Google Workspace mail-merge, and SharePoint links. The stolen accounts are valuable not just for the budget inside them, but because older accounts with…

July 29, 2026
Levi’s Breach Started With IT Helpdesk Impersonation

Levi’s Breach Started With IT Helpdesk Impersonation

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites…

August 10, 2026
Levi’s Breach Tied to Phone-to-Phish Workflow

Levi’s Breach Tied to Phone-to-Phish Workflow

Levi Strauss disclosed a breach after attackers used social engineering to access three employees’ work computers and steal some corporate data. Separately, reporting and Google’s tracking describe a broader campaign where criminals call employees while posing as coworkers or IT, then send them to…

August 10, 2026
RovoBlast Link Seeds AI to Leak Internal Data

RovoBlast Link Seeds AI to Leak Internal Data

Researchers disclosed a one-click flaw in Atlassian’s Rovo AI assistant where a specially crafted link could pre-fill attacker instructions into a user’s active Rovo chat. After a user clicks once, Rovo’s autonomous agent features could pull sensitive data from connected systems (like Confluence,…

August 8, 2026
LoL Friend-Request Bots Push Discord & OnlyFans

LoL Friend-Request Bots Push Discord & OnlyFans

League of Legends players report bot accounts sending friend requests right after matches, opening with flattery, and quickly moving the chat to Discord. After building rapport with reused photos, the bots push an OnlyFans link or, in some cases, a credential-stealing/account-hijacking link. The…

August 7, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026