BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Android “Trapdoor” Ad Fraud Scheme Uncovered

Trapdoor Android malvertising scheme funneled 24 million users into massive ad fraud network.

  • Trapdoor campaign funneled malvertising into ad fraud using 455 malicious Android apps and 183 C2 domains.
  • The operation generated 659 million daily bid requests at its peak, with apps downloaded over 24 million times.
  • Google removed identified apps from the Play Store after disclosure, effectively neutralizing the operation.

Cybersecurity researchers uncovered a sophisticated ad fraud and malvertising operation, dubbed Trapdoor, that targeted Android device users in May 2026. According to a report from HUMAN‘s Satori Threat Intelligence team shared with The Hacker News, the campaign encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control domains, creating a self-sustaining pipeline for multi-stage fraud. Consequently, unsuspecting users downloaded utility-style apps, which then triggered malvertising campaigns that coerced them into installing secondary apps designed for hidden ad fraud.

- Advertisement -

These secondary apps launched hidden WebViews and loaded threat actor-owned HTML5 domains to request ads, a tactic also seen in prior clusters like SlopAds and BADBOX 2.0. At its peak, Trapdoor accounted for 659 million bid requests a day, with traffic primarily originating from the U.S., according to researchers Louisa Abel, Ryan Joye, João Marques, João Santos, and Adam Sell. The operation also abused install attribution tools to enable malicious behavior only for users acquired through threat actor-run ad campaigns, suppressing it for organic downloads.

Meanwhile, the apps employed fake pop-up alerts mimicking update messages to trick users into installing the next-stage payload. The actors used multiple obfuscation and anti-analysis techniques, such as impersonating legitimate SDKs, to evade detection. Following responsible disclosure, Google removed all identified malicious apps from the Play Store, as detailed in HUMAN’s report. Gavin Reid, HUMAN’s CISO, stated, “Trapdoor shows how determined fraudsters turn everyday app installs into a self-funding pipeline for malvertising and ad fraud.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tesla Begins Driverless Cybercab Tests in Austin

Tesla has started engineering tests of its first production Cybercab in Austin, a vehicle...

Oracle E-Business Flaw Actively Exploited

A critical flaw in Oracle Payments (CVE-2026-46817) is being actively exploited to take over...

Tommy Robinson’s son behind his ‘patriotic’ crypto token

British activist Tommy Robinson shilled his son's "Patriotic Bull" cryptocurrency token on X before...

AI Browser Extension Intercepted User Searches

A malicious Chrome extension impersonating the AI search engine Perplexity intercepted and logged user...

Saylor’s MicroStrategy to Sell Bitcoin Amid Crypto Slump

Strategy announced a new program authorizing the sale of up to $1.25 billion worth...

Must Read

Top 5 Testing Tools For Blockchain Applications in 2022

Blockchain apps have been adopted popularly by some prominent industries due to its being a decentralized-designed technology. Furthermore, these apps eliminate the risks that...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading