New Android Ad Fraud Operation Trapdoor Targets Users via Malvertising
Block the 455 malicious Android app hashes and 183 C2 domains identified by Trapdoor to stop the ad fraud pipeline.
Block the 455 malicious Android app hashes and 183 C2 domains identified by Trapdoor to stop the ad fraud pipeline.
Summary
Researchers from HUMAN's Satori Threat Intelligence have uncovered a new ad fraud and malvertising operation called Trapdoor that targets Android device users.
The operation comprises 455 malicious Android apps and 183 command‑and‑control domains that funnel traffic through a multi‑stage fraud pipeline.
Trapdoor injects malicious code into legitimate apps, redirecting users to phishing sites that harvest credentials and payment information.
The threat actor also leverages social engineering to convince users to install the malicious apps from unofficial app stores.
The discovery highlights the growing sophistication of mobile ad fraud campaigns.
The operation was first identified by the research team in early 2026.
Security teams should block the identified app hashes and C2 domains to mitigate the threat.
Key changes
- Trapdoor operation comprises 455 malicious Android apps
- 183 command‑and‑control domains used for fraud pipeline
- Injects malicious code into legitimate apps to redirect users to phishing sites
- Uses social engineering to convince users to install apps from unofficial stores
- Discovered by HUMAN's Satori Threat Intelligence in early 2026