logo

Android.MagicAd trojan displays ads despite all restrictions

ID: b7e0a792-1f1e-5539-8fe2-9aa0824cb7c2

STIX ID: report--b7e0a792-1f1e-5539-8fe2-9aa0824cb7c2

Feed Name: Dr.Web News

Threat Score
70/100

Date Published: 2026-06-04

Date Updated: 2026-06-06

...
...

Doctor Web analysts discovered Android.MagicAd.1, a trojan concealed in 50+ apps distributed through Xiaomi GetApps (and seen in the Samsung Galaxy Store) that persists on infected devices and displays background advertisements by bypassing Android protections. The malware stores encrypted dex payloads inside native libraries, performs anti-analysis/environment checks, hides its icon, creates persistent services and scheduled tasks, and uses multiple device-specific techniques (Intents to system apps, Android Binder, and a media-player/adb simulation method) to render Translucent Activity ad banners without requesting SYSTEM_ALERT_WINDOW; affected apps were removed from stores but remain active on infected devices, and Dr.Web reports detection/removal capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.