logo

Machine learning–powered Android Trojans bypass script-based Ad Click detection

ID: 3cad8cca-c103-568a-9d71-925d0e152ba9

STIX ID: report--3cad8cca-c103-568a-9d71-925d0e152ba9

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers at Dr.Web uncovered an Android click-fraud trojan family (Android.Phantom.*) that uses TensorFlow.js ML models to visually detect and automatically click ads inside a hidden WebView, evading script-based detection. The malware operates in two modes—'phantom' (automated ML-based clicking) and 'signaling' (WebRTC streaming of the virtual browser for remote attacker control), is distributed via Xiaomi GetApps and third-party APK sites (Moddroid, Apkmody) and social channels, and has been embedded into numerous popular mobile games and modified media apps, enabling ad fraud, potential DDoS bot activity, spyware, and data/battery/data-usage abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.