logo

Hackers Leverage Multiple Ad Networks to Attack Adroid Users With Triada Malware

ID: b3811ebe-d71c-5095-8e2f-1a1347e98c7b

STIX ID: report--b3811ebe-d71c-5095-8e2f-1a1347e98c7b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report describes the resurgence of the Triada Android Trojan in a coordinated campaign that leverages compromised advertising accounts and trusted platforms to distribute malware. Attackers evolved from using forged identity documents and CDN/URL shortener obfuscation (2020–2021) to large-scale advertiser account takeovers (2022 onward) and 2025 phishing pre-landers that mimic Chrome updates and use complex redirect chains; Adex analysts attribute over 15% of Android malware detections in Q3 2025 to Triada. The authors call for stronger controls such as mandatory MFA, zero-trust models, and rigorous domain verification to mitigate continued infrastructure abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.