Disrupted: How the “Trapdoor” Ad Fraud Ring Weaponized 455 Android Apps for 659 Million Daily Fake Bids
ID: 113b0ecc-cf3f-552f-98c6-e16dcfcc8cd0
STIX ID: report--113b0ecc-cf3f-552f-98c6-e16dcfcc8cd0
Feed Name: securityonline.info
Trapdoor is a sophisticated, large-scale mobile ad-fraud operation that used 455 malicious Android apps and 183 C2 domains to covertly install secondary apps via fake update prompts, load hidden fullscreen WebViews on victims, and simulate realistic user interactions (touches/swipes) to generate fraudulent ad bid requests; at peak it produced roughly 659 million fraudulent bid requests per day and infected apps were downloaded over 24 million times. The campaign employed advanced anti-analysis measures (attribution abuse, rooting/debugging/VPN checks, native packers, code virtualization, and string encryption) to avoid detection and ensured payload activation only for users arriving via the attackers' ads, making it a persistent, self-sustaining revenue-driven fraud scheme.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
