This technical report details a large-scale ad fraud campaign involving numerous malicious applications found on Google Play, which have collectively been downloaded over 60 million times. The report outlines the identification of 428 URLs as indicators of compromise (IoCs), from which 197 unique domains were extracted. The analysis further reveals that these domains were created between 2019 and 2025, with the majority being registered in the U.K. and administered by Amazon. The report documents the findings from WHOIS queries, DNS resolutions, and the discovery of additional threat artifacts, including email-connected domains and IP addresses. It highlights that two of the identified artifacts have been linked to previous malicious campaigns. The report emphasizes the importance of thorough investigations into these threats to ensure accurate assessments of their potential risks.