A user reports that after installing a 'free VPN' app from a third-party store, their Android phone started showing ads in the notification bar and the battery drains unusually fast. They also notice data consumption is double what it was.
What mobile malware categories BEST describe this behavior, and what specific mechanism is driving the elevated data and battery consumption?
- A.The app is a passive network monitor, and the tunnel it advertises is real while every flow is copied to the operator's collector (the client mirrors each packet before forwarding it): the data figure doubles with each byte traveling twice, and the battery drain comes from the encryption the mirror path adds on top of the ordinary session the user expects, and every byte counted twice by the carrier
- B.The app is likely adware combined with a click fraud or ad-impression fraud component: it displays unsolicited ads (notification adware), silently loads advertising content in a background WebView, and generates fake ad clicks - all consuming data and CPU/battery. The 'VPN' is a lure to get users to install the malicious payload and accept battery-intensive permissions