BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Android “Trapdoor” Ad Fraud Scheme Uncovered

Trapdoor Android malvertising scheme funneled 24 million users into massive ad fraud network.

  • Trapdoor campaign funneled malvertising into ad fraud using 455 malicious Android apps and 183 C2 domains.
  • The operation generated 659 million daily bid requests at its peak, with apps downloaded over 24 million times.
  • Google removed identified apps from the Play Store after disclosure, effectively neutralizing the operation.

Cybersecurity researchers uncovered a sophisticated ad fraud and malvertising operation, dubbed Trapdoor, that targeted Android device users in May 2026. According to a report from HUMAN‘s Satori Threat Intelligence team shared with The Hacker News, the campaign encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control domains, creating a self-sustaining pipeline for multi-stage fraud. Consequently, unsuspecting users downloaded utility-style apps, which then triggered malvertising campaigns that coerced them into installing secondary apps designed for hidden ad fraud.

- Advertisement -

These secondary apps launched hidden WebViews and loaded threat actor-owned HTML5 domains to request ads, a tactic also seen in prior clusters like SlopAds and BADBOX 2.0. At its peak, Trapdoor accounted for 659 million bid requests a day, with traffic primarily originating from the U.S., according to researchers Louisa Abel, Ryan Joye, João Marques, João Santos, and Adam Sell. The operation also abused install attribution tools to enable malicious behavior only for users acquired through threat actor-run ad campaigns, suppressing it for organic downloads.

Meanwhile, the apps employed fake pop-up alerts mimicking update messages to trick users into installing the next-stage payload. The actors used multiple obfuscation and anti-analysis techniques, such as impersonating legitimate SDKs, to evade detection. Following responsible disclosure, Google removed all identified malicious apps from the Play Store, as detailed in HUMAN’s report. Gavin Reid, HUMAN’s CISO, stated, “Trapdoor shows how determined fraudsters turn everyday app installs into a self-funding pipeline for malvertising and ad fraud.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Alphabet Hits Record High as Analysts Up Targets Ahead of I/O 2026

Alphabet stock, trading near all-time highs, has seen a wave of bullish analyst upgrades...

People More Likely to Lie to AI Than Humans, Study Finds

People behave more unethically toward AI customer-service agents than human workers, according to new...

Strive Adds 382 Bitcoin, Boosting Treasury To $1.1 Billion

Strive purchased 382 Bitcoin for roughly $30 million last week, increasing its total holdings...

Crypto’s Luster Dims as Bitcoin Struggles Against Gold

Interest in Bitcoin is now largely from top buyers and institutions, rather than its...

Bitcoin Plummets, Selling Panic Spurs $770M Loss

Bitcoin's price dropped to $76,500 on Monday, erasing nearly all of May's gains amid...

Must Read

How to Buy VPN With Bitcoin Using CyberGhost VPN

In this step-by-step guide, you will learn how to purchase a VPN (Virtual Private Network) subscription using Bitcoin, a popular cryptocurrency, and CyberGhost VPN,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading