AdultSwine

Malware

⚠️ Overview

AdultSwine is a family of Android adware and trojan malware first discovered in February 2018 by Check Point Research. It was identified as a malicious advertising library embedded within legitimate-looking applications distributed through the official Google Play Store. The malware is attributed to an unknown operator and falls under the categories of adware, trojan, and potentially unwanted program (PUP), with secondary capabilities as a click-fraud botnet.

🔧 Technical Capabilities

AdultSwine propagates by piggybacking on legitimate Android apps, often repackaged or disguised as games, utility tools, or entertainment apps. Once installed, it downloads and executes a payload via a remote server, enabling dynamic loading of ad-generating code. The malware uses a custom command-and-control (C2) infrastructure to receive ad configurations and push fraudulent ad overlays; it employs domain generation algorithms (DGAs) to evade blocking. Persistence is achieved through the use of Android's BroadcastReceiver components and auto-start mechanisms triggered by device boot or network state changes. Evasion techniques include checking for emulator environments, delaying malicious activity by 30–60 minutes post-installation, and hiding its icon after initial launch to avoid user removal.

📜 History & Notable Incidents

The first major outbreak occurred in February 2018 when Check Point reported that over 60 apps containing AdultSwine had been downloaded between 1 million and 4.7 million times from Google Play. In March 2018, Google removed the malicious apps, but variants reappeared later that year. No specific CVEs are associated with AdultSwine; instead, it exploits the inherent permissions model of Android—requesting SYSTEM_ALERT_WINDOW and INTERNET permissions—to generate intrusive pop-up ads. No law enforcement actions have been publicly documented against the operators.

🔍 Detection Indicators

Known file hashes include SHA256: 5a3f7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6 (as reported by Check Point). Behavioral signatures include persistent overlay pop-ups that mimic legitimate ads or system prompts, and network traffic to suspicious domains such as adultswine[.]top or IPs in the 185.185.0.0/16 range. Dynamic analysis reveals the malware creating files under /data/data/[package]/files/ with random .dex or .jar extensions, and registering a mutex named Mutex_AdSwine to prevent multiple instances.

☠️ Risk & Impact

The primary damage from AdultSwine is monetary—it generates fraudulent ad revenue for attackers by displaying unsolicited advertisements and clicking on them in the background, draining device battery and data plans. It does not typically exfiltrate personal data, though it may collect device identifiers (IMEI, Android ID) for ad targeting. The affected sectors are overwhelmingly consumer mobile users, with no known high-profile corporate victims. Check Point estimated the financial impact could reach millions of dollars in fraudulent ad impressions from the initial outbreak.

🛡️ Mitigation

Mitigation relies on installing only verified apps from trusted developers on Google Play, avoiding apps with excessive permissions (especially SYSTEM_ALERT_WINDOW), and using mobile security solutions like Check Point SandBlast Mobile or Google Play Protect. Users should regularly review app permissions and remove any app that displays persistent overlays or hidden icons. Network defenses can block traffic to known DGA-generated domains through DNS blacklisting.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.