DoubleVerify finds dozens of Android apps a month showing ads after calls

A recent analysis by DoubleVerify engineers has shed light on a troubling trend in mobile advertising, specifically targeting Android applications. Dubbed AfterCall ads, this phenomenon involves applications that seize control of the screen to display advertisements immediately after a phone call concludes. This practice reportedly generates hundreds of millions of impressions each month, raising significant concerns about user experience and brand integrity.

The scenario the post opens with

Nir Danon, the author of the analysis, illustrates the issue through a relatable scenario: a user experiences persistent advertisements for games or shopping services following each phone call, yet finds no trace of suspicious applications upon inspection. This lack of visibility is intentional, as the AfterCall mechanism is designed to obscure its presence from users. The DoubleVerify Fraud Lab has noted a marked increase in the use of this technique, which, while simple, proves effective in evading detection.

Three components, all of them ordinary

According to DoubleVerify, every AfterCall application operates on a consistent framework comprising three elements: a special permission obtained under misleading pretenses, a Broadcast Receiver that captures end-of-call events, and an Activity that displays the advertisement. Notably, none of these components represent a vulnerability; rather, they are standard Android features functioning as intended.

The permission that makes it possible

The crux of the issue lies in the SYSTEMALERTWINDOW permission, which allows an application to display content over other apps. Unlike standard permissions, this one cannot be granted through the usual in-app dialogue; developers must redirect users to the Settings application, a step designed to encourage careful consideration. However, fraudulent developers exploit this by manipulating the order of permission requests, often leading users to grant overlay access under false pretenses. Danon highlights that many non-technical users, unaware of the implications, may inadvertently consent to these permissions.

Hooking the end of the call

AfterCall applications leverage Android’s communication system to register for telephony Intents. When a call ends, these applications utilize the broadcast signal to trigger the display of an advertisement. The analysis reveals that these applications often set their BroadcastReceiver priority unusually high to ensure they respond first to the end-of-call signal. Additionally, they employ tactics to remain active in memory, thereby increasing the number of opportunities to capture end-of-call events.

The screen the user actually sees

Upon the conclusion of a call, users are presented with a screen that typically includes call details, a misleading explanation of how the advertisement relates to the app’s function, and the advertisement itself. Two notable evasion techniques are employed: the application removes itself from the recent apps list, complicating user identification of the source, and it uses innocuous-looking icons that resemble common utilities, further masking its true nature.

Why the pattern resists standard detection

The DoubleVerify report outlines several reasons why this trend is challenging to detect. Static signatures fail due to the lack of a shared codebase among developers, while behavioral signatures are ineffective because legitimate applications may exhibit similar telemetry. Moreover, user reporting is hampered by the obfuscation tactics employed by these applications, making it difficult for users to pinpoint the source of the disruptive behavior. As a result, these applications often evade the pre-installation scanning conducted by app stores.

Scale, and what it costs the buyer

The scale of the issue is particularly alarming, with the DV Fraud Lab uncovering numerous AfterCall applications each month, collectively responsible for hundreds of millions of impressions. While the report does not provide a regional breakdown or financial estimates of wasted ad spend, it emphasizes the detrimental impact on user experience. Advertisers risk being associated with disruptive software, undermining the effectiveness of their campaigns.

The wider mobile fraud picture in 2026

The emergence of AfterCall ads coincides with heightened scrutiny of mobile inventory. Recent findings indicate that organic traffic constitutes a significant portion of fraudulent mobile installs, complicating the landscape for advertisers. DoubleVerify’s own metrics suggest a decline in overall fraud rates, yet the presence of AfterCall ads highlights the ongoing challenges in ensuring a safe and effective advertising environment.

What it means for buyers of mobile inventory

For media buyers, the challenge lies in the fact that AfterCall impressions may appear legitimate based on standard metrics. These ads are rendered at full size and displayed on real devices, making them difficult to filter out. The core issue is contextual, as the advertisements disrupt user experience rather than stemming from technical flaws. This situation mirrors broader concerns regarding low-quality inventory in mobile environments.

Timeline

  • 2018: DoubleVerify begins providing fraud filtering for mobile in-application campaigns.
  • April 2024: DoubleVerify extends content-level brand safety measurement to mobile applications.
  • Mid-2024: HUMAN Security uncovers Konfety, a mobile fraud campaign.
  • February 2025: Google removes applications tied to a fraud operation from the Play Store.
  • June 25, 2025: DoubleVerify discloses ShadowBot, costing advertisers significantly.
  • August 2025: Google reports a reduction in deceptive ads through enhanced detection methods.
  • September 25, 2025: DoubleVerify highlights a surge in AI-powered fraudulent applications.
  • March 4, 2026: DoubleVerify publishes findings on AI-generated clickbait domains.
  • June 10, 2026: AppsFlyer reports organic traffic as a major source of fraudulent installs.
  • July 7, 2026: DoubleVerify’s benchmarks indicate a decline in fraud rates.
  • July 11, 2026: HUMAN Security disrupts a connected television scheme generating invalid requests.
  • July 13, 2026: DoubleVerify publishes the AfterCall analysis, revealing widespread issues.

Summary

Who: DoubleVerify’s Fraud Lab, through a post by Nir Danon. The applications are attributed to unnamed Android developers.

What: An analysis of AfterCall ads, which are triggered post-call. The mechanism involves deceptive permission requests and broadcasting techniques.

When: July 13, 2026.

Where: Android devices globally, affecting mobile in-application advertising.

Why: DoubleVerify reports uncovering numerous applications responsible for significant impressions, highlighting the need for vigilance among advertisers.

AppWizard
DoubleVerify finds dozens of Android apps a month showing ads after calls