Monday, August 24, 2026

Trapdoor Android Ad Fraud Ring Abuses 455 Apps for Fake Clicks

A large-scale Android ad fraud campaign named “Trapdoor,” exposing a sophisticated ecosystem built on 455 malicious apps and 183 command-and-control (C2) domains.

The operation combines malvertising, automated click fraud, and advanced evasion techniques to create a self-sustaining revenue loop that has generated massive fraudulent traffic across the digital advertising ecosystem.

At its peak, Trapdoor generated approximately 659 million bid requests per day, with associated apps downloaded more than 24 million times.

The campaign is notable for blending multiple fraud stages into a continuous pipeline, allowing threat actors to monetize users repeatedly while avoiding detection.

The infection chain begins with seemingly legitimate Android applications, often disguised as utility tools such as PDF readers, file managers, or device cleaners.

Trapdoor percentage (Source : Satori Threat Intelligence).
Trapdoor percentage (Source : Satori Threat Intelligence).

These apps are distributed through official and third-party channels and appear benign during initial use.

However, once installed, they initiate deceptive advertising campaigns that prompt users to install additional applications under the guise of updates or performance improvements.

HUMAN’s Satori Threat Intelligence and Research Team has identified and has disrupted an ad fraud and malvertising operation dubbed Trapdoor.

These follow-up installations are central to the fraud operation. Unlike the initial apps, the secondary payload apps activate hidden malicious functionality.

They deploy invisible WebViews that load attacker-controlled HTML5 domains and silently request advertisements. Behind the scenes, these apps simulate user interaction with ads using automated touch events, generating fraudulent clicks without the user’s knowledge.

Trapdoor Android Ad Fraud Ring

Trapdoor’s architecture relies on a multi-stage pipeline consisting of distribution, activation, payload execution, and monetization.

Technical Analysis (Source : Satori Threat Intelligence).
Technical Analysis (Source : Satori Threat Intelligence).

One of its most advanced techniques involves abusing mobile install attribution systems. These systems, typically used by marketers to track user acquisition, are manipulated by the attackers to distinguish between organic and ad-driven installs.

Malicious behavior is only triggered when users install apps via attacker-controlled advertising campaigns.

If a security researcher downloads the same app directly from an app store, the app behaves normally, effectively bypassing traditional analysis methods. This selective activation significantly reduces the likelihood of detection.

Once activated, the malware decrypts embedded assets that contain key operational data, including C2 domains and click automation instructions.

These instructions are stored in files such as move.txt and click.txt, which define precise screen coordinates and gesture patterns.


Coordinate plot generated from move.txt movement data, illustrating structured, pre-programmed gesture paths used for automated ad interaction (Source : Satori Threat Intelligence).
Coordinate plot generated from move.txt movement data, illustrating structured, pre-programmed gesture paths used for automated ad interaction (Source : Satori Threat Intelligence).

Using Android’s input dispatch mechanisms, the malware executes realistic tap and swipe sequences designed to interact with specific ad placements.

The fraudulent activity is executed within hidden WebViews configured to remain invisible to users. These views load HTML5-based content hosted on attacker infrastructure, often mimicking gaming or news platforms.

This approach aligns Trapdoor with previously identified operations such as SlopAds, Low5, and BADBOX 2.0, all of which leveraged HTML5 domains as monetization layers.

Code configuring the hidden WebView with flags that suppress any visible indication of its activity (Source : Satori Threat Intelligence).
Code configuring the hidden WebView with flags that suppress any visible indication of its activity (Source : Satori Threat Intelligence).

To evade detection, Trapdoor employs multiple anti-analysis techniques. These include checks for rooted devices, debugging environments, and VPN usage which are commonly associated with security research.

If such conditions are detected, the malicious behavior is suppressed. Additionally, the apps use native code packing, string encryption, and code virtualization to hinder reverse engineering efforts.

Some variants even impersonate legitimate advertising SDKs to blend into normal application behavior.

HUMAN has deployed protections against Trapdoor through its advertising security platform, mitigating the impact of fraudulent traffic generated by these apps.

However, researchers warn that the threat actors continue to evolve the operation by releasing new apps and rotating infrastructure.

Trapdoor highlights a growing trend in which threat actors weaponize legitimate advertising technologies and infrastructure to scale fraud operations.

By combining deceptive distribution, selective activation, and automated monetization, the campaign demonstrates how modern ad fraud has become both highly adaptive and difficult to detect.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Zimbra Collaboration Suite Flaw Actively Exploited to Execute Arbitrary Commands

Threat actors are actively exploiting a critical operating system...

Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign

Open VSX has removed three extension identifiers from its...

New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks

SynkLoader, a newly identified modular malware framework that combines...

New macOS Malware Clones Your Logged-In Browser and Gives Hackers Remote Control.

AmnesiaStealer, a multi-stage macOS infostealer written in Rust that...

Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers

Microsoft is currently investigating a compatibility issue with Windows...

Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access

A critical vulnerability has been identified in the widely...

AWS Network Firewall Adds Rule Hit Counts to Identify Unused Security Rules

AWS has introduced a new capability for AWS Network...

macOS ClickFix Crimekit Uses Polygon Smart Contracts to Deploy AMOS Stealer and XMRig Miner

A macOS-focused ClickFix campaign is abusing Polygon smart contracts...

Related Articles

Recent News