Android VPN apps found serving disruptive ads

VPN App
Image credit: Shutterstock (Image credit: Shutterstock)

A security researcher has discovered four VPN apps that serve ads while running in the background and also on the home screen of Android smartphones in the latest case of adware found on the Google Play Store.

While researching suspicious Android VPN apps, Andy Michael found that Hotspot VPN, Free VPN Master, Secure VPN and Security Master by Cheetah Mobile were all showing full screen pop-up ads on his smartphone even though none of these apps were currently open.

It is also worth noting that all of these apps originate from either Hong Kong or China where VPN usage tends to be higher than in other countries due to China's Great Firewall and the ongoing protests in Hong Kong. While three of the four apps provide VPN services to users, Security Master is an antivirus app. 

All of the apps found to be showing disruptive ads by Andy Michael are still available on the Play Store at the time of writing.

Adware apps

In addition to APIs from Google and Facebook used to show ads, Michael's investigation also found that Hotspot VPN also contained obfuscated code which is used to show full-screen ads regardless of whether or not the app is currently open which results in significant battery and CPU usage. This app's name also resembles the legitimate VPN, Hotspot Shield and its developer likely chose this name as a way to trick unsuspecting users into downloading their app instead.

Free VPN Master was found to share the same code for serving Google ads and its APK file has the same code structure and files as Hotspot VPN. According to Michael, both apps are identical apart from slight modifications in their code.

Secure VPN though was the worst offender as it served ads when users had other apps open and even overlaid them on top of user's home screens. The app also contained references to code that recorded activities such as when an ad was displayed, clicked on or dismissed by the user. Security Master on the other hand, used more sophisticated behavior to show ads when users tried to go back to the home screen or when certain buttons were clicked.

Android users are constantly warned to avoid installing apps from unknown sources but when they can't even trust Google's own Play Store to find legitimate apps, there is a serious problem.

  • Worried about downloading a fake VPN app? Check out our complete list of the best VPN services of 2019

Via TNW

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in VPN
Close up of PS5 DualSense controller leaning on a PS5
5 reasons your PS5 needs a VPN
Harry Halpin, CEO and co-founder of Nym Technologies, and Chelsea Manning, Nym Technlogies' security consultant, on stage at the Frontline Club in London during the NymVPN launch on March 13, 2025.
NymVPN is now live – here's everything you need to know
Tor
What is Onion over VPN?
A representational concept of a social media network
What are data removal services?
ExpressVPN's Lightway Turbo upgrade – promo image
Can fast be faster? ExpressVPN promises it’s possible
AdGuard VPN during TechRadar tests
AdGuard becomes the latest VPN to add post-quantum encryption
Latest in News
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Ray-Ban smart glasses with the Cpperni logo, an LED array, and a MacBook Air with M4 next to ecah other.
ICYMI: the week's 7 biggest tech stories from Twitter's massive outage to iRobot's impressive new Roombas
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight