logo

Trapdoor Android Ad Fraud Operation Uses 455 Malicious Apps to Generate Fake Clicks

ID: 8c5e9d4f-5f59-5975-84c9-3d2dddafe299

STIX ID: report--8c5e9d4f-5f59-5975-84c9-3d2dddafe299

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-20

Date Updated: 2026-05-21

Author: Tushar Subhra Dutta

...
...

Trapdoor is a sophisticated, large-scale Android ad-fraud campaign in which 455 apps (collectively downloaded over 24 million times) install secondary payloads that open hidden browser windows and simulate human touch gestures to generate fake ad clicks; researchers observed up to 659 million fraudulent bid requests in a single day. The operation uses selective activation (triggered only for paid installs), code packing, string encryption, anti-analysis checks, and impersonation of legitimate SDKs to evade detection, and researchers published IoCs including bundled files (move.txt, click.txt), C2 domains, a malicious app list, and an /api/referrer endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.