Your Android phone suddenly appears after the phone? This is the culprit!

Have you ever seen an Android phone screen suddenly filled with pop-up ads right after you hung up? This annoying symptom has recently been widely experienced by many users. Many think their device is infected with a malignant virus or suspects the ad is the official default of the operator. In fact, you are most likely the target of the latest digital advertising scam trend that is designed to be very cunning.
Not just annoyed, AfterCall mode is stalking Android users
Based on the latest cyber security report adapted from Cybernews, this phenomenon is known as a threat “Aftercall Ad Fraud”. The rogue application developers deliberately designed this tactic to make financial gain from hundreds of millions of illegal ad impressions without capturing the attention of users when opening the application.
Adapted from the results of the in-depth research of the DoubleVerify (DV) Fraud Lab team, there was a significant spike in out-of-context applications (out-of-context apps) which takes advantage of post-call momentum to bombard the phone screen. According to Nir Danon, cybersecurity researcher from DoubleVerify Engineering, this ad appears suddenly outside the context of normal application use. As a result, lay users are deceived and have difficulty tracking which applications are actually the culprits.
This problem-carrying application is generally disguised as a daily utility tool that seems very safe and useful, such as alarm clock applications, calendars, taking notes, to memory cleaners.
How does AfterCall fraud mode work in the background?
Technically, in order to master your phone screen, rogue developers launch a systematic strategy in three main stages:
- Special Access Permit Manipulation: Normally, Android apps are not allowed to take over full screen at will. However, this fraudulent application manipulates the initial registration flow by asking for permission “display over other apps” (show above other apps) or system permissions
System_Alert_Window. A fictitious alarm application, for example, argues that this permission must be given so that the alarm can still sound when the cellphone screen is locked. - LOOKING AT THE PHONE SIGNAL (TELEPHONY INTENTS): After the granted permission, the application embeds a surveillance function called
BroadcastReceiver. Android system uses internal message signal named INTENTS to notify the application when a call occurs. When the call starts, the phone’s status changes toringing, and when the call ends, the status changes toidle. - Auto ad launch: Signal
idleThis is what a malicious script is waiting for. As soon as the phone call is closed, the app immediately launches a special interface that displays fake details as if the phone’s built-in features, the bottom of which is filled with paid advertising banners.
The cunning trick to remove traces from recent apps
DoubleVerify researchers revealed that threat developers Advertisement After Android Phone This is very clever in avoiding suspicion. Right after the ad is shown, the app automatically removes itself from the list Recent Apps (last application). So, when the user tries to press the navigation key to check what apps just triggered the ad, the app list screen won’t show any traces of it.
“This fraud application deliberately uses icons that resemble essential tools such as clocks or calendars, then deletes traces of recent apps to reduce uninstall numbers and continue to drain ad revenue,” said Nir Danon in a statement.
Why do Google Play Antivirus and Scanning often pass?
Why can the Google Play Protect security scanner system be missed? Based on the technical analysis of CyberNews, legitimate applications such as telephone number detectors (Caller ID) also use the same call signal component. This creates a dynamic signature scan (Dynamic Signatures) Difficulty distinguishing which applications have good intentions and which are to cheat.
The impact of this fraud mode is not only detrimental to advertisers whose budgets are wasted, but also drain the phone’s battery life, slow down system performance, and drastically intrude on user privacy and comfort.
concrete steps to clean android phone from aftercall ads
If your device is already infected with a problem Advertisement After Android Phone, the editorial team of Lidahtekno suggests the following cleaning steps:
- Permission audit “Show above other apps”: Open the menu Settings (Settings) > Applications (apps) > Special Access (Special App Access) > elect Show above other apps (display over other apps). Turn off this permission for utility, alarm, or record-recording third-party apps.
- Remove suspicious utility apps: Check the list of installed applications. Delete the free utility application that is installed right before the post-phone ad phenomenon begins to appear.
- Use Safe Mode if it’s still stubborn: If the application refuses to be deleted normally, go to Safe Mode (Safe Mode) Android to remove it cleanly without scripting interruption in the background.
Conclusion of the editor of Lidahtekno
The rise of threats Advertisement After Android Phone Being an important reminder so that we don’t carelessly give high-level access permissions on simple utility applications. Always look out for other user reviews as well as the reputation of the developer before downloading the free app in the app store.























