logo

New Android malware uses AI to click on hidden browser ads

ID: b65f7243-fa8a-5cdf-8a47-fd76cfa1777a

STIX ID: report--b65f7243-fa8a-5cdf-8a47-fd76cfa1777a

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2026-01-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers at Dr.Web discovered an Android click-fraud trojan family distributed through Xiaomi's GetApps and third‑party APK/communication channels that leverages TensorFlow.js models to visually identify and tap advertisement elements inside hidden WebView instances (phantom mode) or stream the virtual screen to operators via WebRTC for manual control (signalling mode). Multiple infected apps with thousands of downloads were identified, and distribution occurs via app updates, modified popular apps, Telegram channels and a Discord server; the activity is covert and primarily causes ad fraud, battery and data drain rather than direct data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.