Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps
ID: fa866e5e-d5e9-5487-98e8-466e6b936574
STIX ID: report--fa866e5e-d5e9-5487-98e8-466e6b936574
Feed Name: The Hacker News
Researchers disclosed "Trapdoor," a large Android-focused malvertising and ad-fraud campaign that leveraged 455 malicious apps and 183 C2 domains to create a self-sustaining fraud pipeline—peaking at ~659 million bid requests/day and over 24 million app downloads—by using multi-stage app installs, hidden WebViews loading HTML5 cashout domains, install-attribution abuse, selective activation for ad-acquired users, and multiple anti-analysis/obfuscation techniques; Google removed the identified apps following disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
