Is Your Phone Always Low on Battery and Chewing Through Data? 'DrainerBot' Could Be to Blame, Oracle Says.

Advertisement
By Brian Fung, The Washington Post | Updated: 21 February 2019 12:21 IST
Highlights
  • The software affects hundreds of Android apps
  • The code works by quietly downloading gigabytes of video ads
  • It then displays them to users of apps that have been infected

A sneaky piece of advertising software may be responsible for driving up millions of Android users' mobile data usage and wasting their device's battery life, according to researchers at the technology company Oracle.

The code, which Oracle said Wednesday is at the heart of a massive ad fraud operation that it's calling "DrainerBot," works by quietly downloading gigabytes of video ads to a consumer's smartphone and then displays them - invisibly - to users of apps that have been infected by the bot.

The software affects hundreds of Android apps that have been downloaded collectively more than 10 million times, the researchers said.

Advertisement

Because the invisible advertisements rely on the phone's mobile data connection and processing power, the bot can lead to more than 10 GBs of extra data usage per month, Oracle said, exposing some cellphone users to possible data overage fees.

Advertisement

Consumers aren't the only ones potentially harmed by the bot, said Eric Roza, senior vice president at Oracle. The bot wastes marketers' money by selling ads that nobody sees, and it tarnishes the app developers who were likely unaware of its existence, he said.

"This is a crime with three layers of victims," he said in an interview. "I hadn't seen anything like this before."

Advertisement

Oracle's researchers first stumbled across DrainerBot last summer, when network analysts flagged a suspicious spike in data traffic from some Android devices. Soon the company traced the bot's code to a Dutch firm that specialises in combating app piracy.

The Dutch company, Tapcore, released a statement Wednesday saying it had no involvement in the scheme. Tapcore's main business aims to help app developers get paid, through advertising, when software pirates use their apps illegally.

Advertisement

"Tapcore strongly denies any intentional involvement in this supposed ad fraud scheme and are extremely surprised by the Oracle findings. We've already launched a full scale internal investigation to get to the bottom of it and will be providing updates as they become available."

Tapcore's software is ordinarily integrated into other apps before they're published, and only serves ads to users who acquired the apps illegitimately, according to its website. Downloading an app with Tapcore's code in it from the Google Play Store, for example, is not supposed to trigger the advertising. Tapcore's offer to advertisers does not appear to mention the ad bot.

In a statement Wednesday, Google said it has blacklisted all of the infected apps identified by Oracle and is investigating the two remaining apps cited by Oracle that were still active on the Google Play Store. The other apps on Oracle's list either never appeared on Google's app store, or were removed previously for other reasons.

"Google Play developer policies prohibit deceptive and malicious behaviour on our platform. If an app violates our policies, we take action," Google said.

There is little reason to expect that app developers or app store operators would have detected DrainerBot during the normal development process, Oracle said.

After lying dormant for a period of time within an infected app, the infected software kit distributed by Tapcore was programmed to reach out to a server and download additional code that ultimately activated DrainerBot. Oracle said the intentional delay likely made it harder to detect the plot. Oracle said it was notifying the public of the ad fraud operation to protect the value of legitimate advertising.

Ad industry groups are expected to brief marketers on DrainerBot later this week.

"We are delighted to work with Oracle to educate and inform TAG's membership about this emerging threat," said Mike Zaneis, chief executive of the Trustworthy Accountability Group, which is led by companies such as Disney, Google and Facebook.

© The Washington Post 2019

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: DrainerBot, Oracle
Advertisement
Popular Mobile Brands
  1. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  2. AI Impact Summit: From Registration to Schedule, All You Need to Know
  3. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  4. Xiaomi 17 Series Leak Hints at Imminent Launch Ahead of MWC at These Prices
  5. PS6 Could Reportedly be Delayed to 2029 Due to RAM Shortage
  6. Poco X8 Pro Spotted on Geekbench With This Dimensity 8000 Series Chipset
  7. Deals on iPhone 17, Google Pixel 10 and More During Flipkart Sale
  1. Sony Could Reportedly Delay PS6 to as Late as 2029 Due to RAM Shortage
  2. iPhone 18 Series to Drop SIM Card Slot in Europe to Make Room for Slightly Larger Battery: Report
  3. Poco X8 Pro Spotted on Geekbench With MediaTek Dimensity 8500 Ultra SoC, Android 16
  4. Xiaomi 17, Xiaomi 17 Ultra Global Price Details, Launch Date and Colour Options Leaked
  5. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  6. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  7. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  8. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  9. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  10. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.