VYPR
researchPublished Jul 27, 2026· 1 source

Aftercall Campaign Floods Android Users with Intrusive Ads via Google Play Apps

A deceptive Android app campaign dubbed 'Aftercall' is bombarding users with intrusive, full-screen ads after every phone call, exploiting Google Play and user trust.

A widespread campaign targeting Android users, dubbed 'Aftercall,' is causing significant frustration by injecting intrusive, full-screen advertisements that appear immediately after every phone call. These deceptive applications, distributed through the official Google Play Store, masquerade as legitimate utilities such as alarm clocks, calendars, or system cleaners. Their primary objective is to generate ad impressions by exploiting a specific Android permission: 'appear on top.'

Once installed, these apps cunningly request the 'appear on top' permission, which allows them to overlay their content over other running applications. To gain this critical permission, the apps often present users with fabricated scenarios, such as needing to ensure alarms function correctly even when the device is locked, or simply blocking the user interface until the permission is granted. This social engineering tactic bypasses standard Android permission prompts, directing users to the system settings where manual approval is required.

After obtaining the necessary permissions, the Aftercall apps actively monitor the phone's call state. Upon detecting the end of a call, they immediately trigger an ad display. To further disguise their malicious intent, these ads are often wrapped in a fake 'call information' screen, complete with user-like profile pictures and text that mimics legitimate post-call features. This deceptive layer aims to make the intrusive ads appear as a natural extension of the phone's calling functionality, rather than an unrelated advertisement.

Adding to the user's difficulty in identifying and removing the offending apps, Aftercall applications employ stealth tactics. They actively remove themselves from the 'Recent apps' list, rendering the common method of closing suspicious applications ineffective. This makes it challenging for users to pinpoint the source of the disruptive ads, leading to prolonged annoyance and potential security risks.

The scale of the Aftercall campaign is substantial, with researchers identifying dozens of new malicious apps being released monthly. Collectively, these apps are responsible for generating hundreds of millions of ad impressions. While primarily an annoyance, such campaigns can also waste advertisers' money and potentially lead users to click on malicious links embedded within the ads.

To combat this threat, users are advised to scrutinize apps that have 'appear on top' or 'display over other apps' permissions. Checking Settings > Apps > Special access > Appear on top can reveal which applications have this capability. Users should revoke this permission for any app that does not require it for its core functionality, such as simple note-taking or clock applications. If an app is identified as the culprit, it should be uninstalled immediately.

Furthermore, maintaining up-to-date anti-malware software, ensuring Google Play Protect is enabled and actively scanning, and exercising caution when granting app permissions are crucial preventative measures. Users should always question whether an app truly needs the access it requests to perform its stated function, thereby reducing the likelihood of falling victim to deceptive campaigns like Aftercall.

Synthesized by Vypr AI