A large-scale Android ad fraud campaign named “Trapdoor,” exposing a sophisticated ecosystem built on 455 malicious apps and 183 command-and-control (C2) domains.
The operation combines malvertising, automated click fraud, and advanced evasion techniques to create a self-sustaining revenue loop that has generated massive fraudulent traffic across the digital advertising ecosystem.
At its peak, Trapdoor generated approximately 659 million bid requests per day, with associated apps downloaded more than 24 million times.
The campaign is notable for blending multiple fraud stages into a continuous pipeline, allowing threat actors to monetize users repeatedly while avoiding detection.
The infection chain begins with seemingly legitimate Android applications, often disguised as utility tools such as PDF readers, file managers, or device cleaners.

These apps are distributed through official and third-party channels and appear benign during initial use.
However, once installed, they initiate deceptive advertising campaigns that prompt users to install additional applications under the guise of updates or performance improvements.
HUMAN’s Satori Threat Intelligence and Research Team has identified and has disrupted an ad fraud and malvertising operation dubbed Trapdoor.
These follow-up installations are central to the fraud operation. Unlike the initial apps, the secondary payload apps activate hidden malicious functionality.
They deploy invisible WebViews that load attacker-controlled HTML5 domains and silently request advertisements. Behind the scenes, these apps simulate user interaction with ads using automated touch events, generating fraudulent clicks without the user’s knowledge.
Trapdoor Android Ad Fraud Ring
Trapdoor’s architecture relies on a multi-stage pipeline consisting of distribution, activation, payload execution, and monetization.

One of its most advanced techniques involves abusing mobile install attribution systems. These systems, typically used by marketers to track user acquisition, are manipulated by the attackers to distinguish between organic and ad-driven installs.
Malicious behavior is only triggered when users install apps via attacker-controlled advertising campaigns.
If a security researcher downloads the same app directly from an app store, the app behaves normally, effectively bypassing traditional analysis methods. This selective activation significantly reduces the likelihood of detection.
Once activated, the malware decrypts embedded assets that contain key operational data, including C2 domains and click automation instructions.
These instructions are stored in files such as move.txt and click.txt, which define precise screen coordinates and gesture patterns.

Using Android’s input dispatch mechanisms, the malware executes realistic tap and swipe sequences designed to interact with specific ad placements.
The fraudulent activity is executed within hidden WebViews configured to remain invisible to users. These views load HTML5-based content hosted on attacker infrastructure, often mimicking gaming or news platforms.
This approach aligns Trapdoor with previously identified operations such as SlopAds, Low5, and BADBOX 2.0, all of which leveraged HTML5 domains as monetization layers.

To evade detection, Trapdoor employs multiple anti-analysis techniques. These include checks for rooted devices, debugging environments, and VPN usage which are commonly associated with security research.
If such conditions are detected, the malicious behavior is suppressed. Additionally, the apps use native code packing, string encryption, and code virtualization to hinder reverse engineering efforts.
Some variants even impersonate legitimate advertising SDKs to blend into normal application behavior.
HUMAN has deployed protections against Trapdoor through its advertising security platform, mitigating the impact of fraudulent traffic generated by these apps.
However, researchers warn that the threat actors continue to evolve the operation by releasing new apps and rotating infrastructure.
Trapdoor highlights a growing trend in which threat actors weaponize legitimate advertising technologies and infrastructure to scale fraud operations.
By combining deceptive distribution, selective activation, and automated monetization, the campaign demonstrates how modern ad fraud has become both highly adaptive and difficult to detect.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





