logo

Phantom Malware in Android Game Mods Hijacks Devices for Ad Fraud

ID: 2a838d13-c623-5d5a-af59-4e5b505f4f51

STIX ID: report--2a838d13-c623-5d5a-af59-4e5b505f4f51

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Waqas

...
...

Researchers at Doctor Web reported an Android malware family called Android.Phantom distributed via modified game APKs and third‑party stores that runs covert ad‑fraud: it loads webpages in a hidden browser, downloads scripts and machine‑learning models to mimic user clicks, and can provide remote controllers real‑time interaction via WebRTC; affected apps appear to function normally while fraud runs in the background and the toolkit uses modular droppers and frequent updates to broaden its capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.