A banner delivered by an advertising SDK included in several legitimate applications for Android smartphones was found deploying a scareware-type attack on innocent users. An alarmist banner pops-up out of the blue on the handset screen making users believe their devices are infected with malware and prompts them towards purchasing a useless disinfection tool. The scam appeared as a pop-up ad delivered by a pop up ad delivered as a. legitimate. advertising module. Most likely the providers of the advertising module are not aware their service is delivering a malicious banner. It appears to be a case of an invalidated ad that accidentally reached the market.”]