logo

MobiDash internals: ghost clicks and SSH tunnels in commercial adware

ID: 87a81969-1d7e-5cad-86f9-c444a473fdcd

STIX ID: report--87a81969-1d7e-5cad-86f9-c444a473fdcd

Feed Name: Jamf Blog

Threat Score
72/100

Date Published: 2026-02-26

Date Updated: 2026-07-16

...
...

This report analyzes the MobiDash Android adware family: a sophisticated repackaging/injection framework that embeds into legitimate APKs to perform stealthy ad fraud via scripted WebView interactions (synthetic MotionEvent), virtual/offscreen rendering, per-banner proxying (reverse SSH/SOCKS5) for geo-spoofing or bandwidth resale, and dynamic code/config delivery via InMemoryDexClassLoader; it includes anti-analysis checks, ad-SDK identity spoofing, and IOCs and remediation guidance for enterprise defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.