Google disclosed that the Android potentially harmful application family Chamois operated as a large fraud botnet that targeted both users and Google's advertising ecosystem. The malware generated ad fraud through deceptive pop-up ads, promoted apps via background installations, carried out premium SMS fraud, and downloaded additional plugins, while relying on a four-stage payload, obfuscation, and encrypted storage to avoid detection. Google said it identified the activity through ad traffic quality analysis, blocked the apps with Verify Apps, and removed actors abusing its advertising platforms.
Separate reverse-engineering research showed that multiple Android malware families, including Chamois variants, used an anti-analysis native library dubbed WeddingCake to conceal malicious behavior and frustrate defenders. Packaged as an Android ELF shared object, the library decrypted hidden strings during JNI_OnLoad, dynamically registered native methods, and used a function identified as vxeg() to run more than 45 checks for emulators, instrumentation, the Monkey testing tool, CPU inconsistencies, and the Xposed Framework; if an analysis environment was detected, the app terminated with exit(0). The researcher reported finding WeddingCake in more than 5,000 unique Android APKs, underscoring how broadly the evasive component was deployed.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
A Virus Bulletin 2018 paper by Maddie Stone analyzed an Android anti-analysis native library dubbed WeddingCake, which was used by multiple malware families including some Chamois variants. The paper reported WeddingCake in more than 5,000 unique Android APKs and detailed its JNI obfuscation, string decryption, and more than 45 anti-emulation and anti-instrumentation checks that terminate apps when analysis is detected.
Google said it implemented Verify Apps protections against Chamois and blocked the family to protect Android users. It also removed bad actors who were attempting to abuse Google's advertising systems.
On the Android Developers Blog, Google disclosed Chamois as a newly identified Android potentially harmful application family involved in ad fraud, background app installs, premium SMS fraud, and plugin downloads. Google said it had detected Chamois during ad traffic quality evaluation and described it as one of the largest Android PHA families seen on Android.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
virusbulletin.com
Open sourceandroid-developers.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.