Investigation: 8 apps with a total of 2B+ downloads from Google Play, including 7 from Cheetah mobile, exploit user permissions in an ongoing ad fraud scheme
Eight apps with a total of more than 2 billion downloads in the Google Play store have been exploiting user permissions as part …
Context & Ripple Effects
This investigation lands mid-arc in a string of Android ad-fraud exposés: Check Point had already flagged 41 apps from a single developer fraudulently clicking ads in 2017, and weeks earlier BuzzFeed mapped a network of 125+ apps and websites running a massive ad fraud scheme. What makes this one different is scale and pedigree — eight apps with more than 2 billion combined downloads, seven of them from Cheetah Mobile, one of the most prominent Chinese developers on Google Play.
The story also sets up what came next: within a week, Google ran its own internal investigation and removed two Cheetah Mobile and Kika Tech apps for click-injection fraud (Google's removal of Cheetah Mobile and Kika Tech apps), and months later the same playbook surfaced at DU Group in six more Android apps abusing user permissions. The through-line is that ad fraud was not confined to obscure shovelware — it sat inside top-grossing publishers' catalogs.
First-order effects
- Cheetah Mobile's entire Play Store portfolio comes under advertiser and platform scrutiny, since seven of its apps are named as exploiting user permissions in an ongoing scheme — its brand, not just individual listings, is now the liability.
- Advertisers buying inventory through these high-download apps have been paying for engagement generated by abused permissions rather than real user interest, making the fraud a direct cost on ad buyers right now.
Second-order effects
- Google is pushed from passive hosting toward active enforcement — a pressure that materialized days later when it removed Cheetah Mobile and Kika Tech apps after its own click-injection investigation.
- Other large Chinese developers get pulled into the same investigative frame, as the DU Group findings show reporters applying the same permission-abuse template to new targets.
Third-order effects
- If the pattern holds, app-store economics shift toward policing the SDK and permission layer rather than reviewing apps at submission — a governance gap where embedded code can commit fraud across billions of installs after approval.
- Repeated mega-scale fraud findings erode trust in download counts as a quality signal, pressuring both stores and advertisers to weight engagement verification over install volume when pricing mobile ads.
The trend: Android ad fraud keeps resurfacing inside major Chinese developers' flagship apps, with store enforcement arriving only after journalists expose schemes that survived initial review.