BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Android “Trapdoor” Ad Fraud Scheme Uncovered

Trapdoor Android malvertising scheme funneled 24 million users into massive ad fraud network.

  • Trapdoor campaign funneled malvertising into ad fraud using 455 malicious Android apps and 183 C2 domains.
  • The operation generated 659 million daily bid requests at its peak, with apps downloaded over 24 million times.
  • Google removed identified apps from the Play Store after disclosure, effectively neutralizing the operation.

Cybersecurity researchers uncovered a sophisticated ad fraud and malvertising operation, dubbed Trapdoor, that targeted Android device users in May 2026. According to a report from HUMAN‘s Satori Threat Intelligence team shared with The Hacker News, the campaign encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control domains, creating a self-sustaining pipeline for multi-stage fraud. Consequently, unsuspecting users downloaded utility-style apps, which then triggered malvertising campaigns that coerced them into installing secondary apps designed for hidden ad fraud.

- Advertisement -

These secondary apps launched hidden WebViews and loaded threat actor-owned HTML5 domains to request ads, a tactic also seen in prior clusters like SlopAds and BADBOX 2.0. At its peak, Trapdoor accounted for 659 million bid requests a day, with traffic primarily originating from the U.S., according to researchers Louisa Abel, Ryan Joye, João Marques, João Santos, and Adam Sell. The operation also abused install attribution tools to enable malicious behavior only for users acquired through threat actor-run ad campaigns, suppressing it for organic downloads.

Meanwhile, the apps employed fake pop-up alerts mimicking update messages to trick users into installing the next-stage payload. The actors used multiple obfuscation and anti-analysis techniques, such as impersonating legitimate SDKs, to evade detection. Following responsible disclosure, Google removed all identified malicious apps from the Play Store, as detailed in HUMAN’s report. Gavin Reid, HUMAN’s CISO, stated, “Trapdoor shows how determined fraudsters turn everyday app installs into a self-funding pipeline for malvertising and ad fraud.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

UN Security Council to Hear AI CEOs on Risks Before Trump-Xi Meet

Anthropic, OpenAI, DeepSeek, and Moonshot will brief the UN Security Council on AI risks...

OpenAI launches cheaper GPT-6 Sol and Luna for coding and work tasks

OpenAI launched GPT-6 Sol at $2 per million input tokens and $10 per million...

Kalshi bot stops uniform trades amid wash trade claims

A trading bot repeatedly buying and selling $1 contracts on Kalshi's Zohran Mamdani prediction...

Six Canadian banks explore tokenized CAD deposits

Canada’s six largest banks jointly explore tokenized Canadian dollar deposits to enable digital bank...

Critical AI Gateway Bug Allows Unauthenticated RCE

A critical unauthenticated remote code execution vulnerability (CVE-2026-90898, CVSS 9.8) affects all versions of...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading