BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Android “Trapdoor” Ad Fraud Scheme Uncovered

Trapdoor Android malvertising scheme funneled 24 million users into massive ad fraud network.

  • Trapdoor campaign funneled malvertising into ad fraud using 455 malicious Android apps and 183 C2 domains.
  • The operation generated 659 million daily bid requests at its peak, with apps downloaded over 24 million times.
  • Google removed identified apps from the Play Store after disclosure, effectively neutralizing the operation.

Cybersecurity researchers uncovered a sophisticated ad fraud and malvertising operation, dubbed Trapdoor, that targeted Android device users in May 2026. According to a report from HUMAN‘s Satori Threat Intelligence team shared with The Hacker News, the campaign encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control domains, creating a self-sustaining pipeline for multi-stage fraud. Consequently, unsuspecting users downloaded utility-style apps, which then triggered malvertising campaigns that coerced them into installing secondary apps designed for hidden ad fraud.

- Advertisement -

These secondary apps launched hidden WebViews and loaded threat actor-owned HTML5 domains to request ads, a tactic also seen in prior clusters like SlopAds and BADBOX 2.0. At its peak, Trapdoor accounted for 659 million bid requests a day, with traffic primarily originating from the U.S., according to researchers Louisa Abel, Ryan Joye, João Marques, João Santos, and Adam Sell. The operation also abused install attribution tools to enable malicious behavior only for users acquired through threat actor-run ad campaigns, suppressing it for organic downloads.

Meanwhile, the apps employed fake pop-up alerts mimicking update messages to trick users into installing the next-stage payload. The actors used multiple obfuscation and anti-analysis techniques, such as impersonating legitimate SDKs, to evade detection. Following responsible disclosure, Google removed all identified malicious apps from the Play Store, as detailed in HUMAN’s report. Gavin Reid, HUMAN’s CISO, stated, “Trapdoor shows how determined fraudsters turn everyday app installs into a self-funding pipeline for malvertising and ad fraud.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tesla’s Full Self-Driving Approved in Denmark

Tesla Inc has secured approval for its Full Self-Driving (FSD) Supervised software from the...

Florida Man Funds Bitcoin Buys via IRS Tax Payment Plan

A Florida man used his tax liability to purchase Bitcoin, opting for an IRS...

Bitcoin Serves as ‘Canary in Coal Mine’ for Risk

Bitcoin is acting as a leading indicator, signaling broader market risk-off sentiment before equities...

Meta Expands AI Data Use for Feeds, Chatbots

Meta will now use data from other businesses to personalize user feeds and AI...

Micron Stock Targets Hit $1500 on AI Chip Boom

Micron Technology's stock closed at $949.28 on June 8, 2026, up nearly 10% for...

Must Read

Top 10 Best Blockchain Games

If you want to know about the best blockchain games then read this article carefully. We listed the best games you can play and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading