Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

Android.Phantom

Android.Phantom is an Android trojan clicker family used for ad-click fraud on infected smartphones. Doctor Web reported it in January 2026 and linked its distribution to trojanized games and modified apps, including pirated mods of popular applications and streaming apps. The malware was observed in unofficial app sources such as third-party stores, APK portals, malicious websites, Telegram channels, Discord servers, and online software collections, and it was also found in Xiaomi’s official GetApps catalog. Reporting states that several infected GetApps titles were tied to developer SHENZHEN RUIREN NETWORK CO., LTD., and that previously clean apps received malicious updates in late September 2025. Mentioned trojanized titles include Creation Magic World, Cute Pet House, and Theft Auto Mafia. More than 155,000 downloads of compromised games were reported, and spread also occurred through modified versions of Spotify, YouTube, Netflix, and Deezer on unofficial platforms.

Android.Phantom operates in two modes controlled by attacker command servers, described as “phantom” and a WebRTC-based signaling/remote-control mode. In phantom mode, it launches alongside the trojanized app without visible alerts, uses a hidden browser/WebView to load attacker-specified websites, and downloads JavaScript automation code plus machine-learning components to analyze ads and perform clicks. The malware uses TensorFlowJS and externally downloaded machine-learning models to analyze webpage or advertisement screenshots, identify clickable ad elements, and mimic real user interactions at scale. If WebRTC is available, Android.Phantom can establish peer-to-peer connections and broadcast a virtual screen of the loaded website, allowing operators to view and interact with the infected device in real time, including scrolling, tapping, and text input, either manually or with automation. If WebRTC is unavailable, it falls back to downloaded JavaScript scripts and TensorFlowJS models from remote servers to automate interactions.

Doctor Web reported that Android.Phantom has been regularly updated and includes additional modules, including a dropper component identified in reporting as Android.Phantom.5, which retrieves remote code loaders and further click-fraud modules from multiple servers to broaden targeting across advertising platforms. Android.Phantom.2.origin was described as the primary variant. High-confidence indicators and characteristics directly mentioned in the content include use of WebView, WebRTC, JavaScript, TensorFlowJS, remote command servers, and externally hosted machine-learning models/scripts. The malware’s core objective is covert large-scale ad fraud while the bundled apps continue to appear functional to the user.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1189Drive-by CompromiseEvidence1

Cybercriminals distributed them in several ways: via the GetApps app catalog for Xiaomi devices, Telegram channels, Discord servers, third-party software collections, and malicious sites.

Execution

1 technique
T1059.007JavaScriptEvidence1

The trojans load target websites along with JavaScript code for simulating user actions in WebView... automated JavaScript scripts utilizing the TensorFlowJS framework are used.

Stealth

1 technique
T1036MasqueradingEvidence1

Members of the Android.HiddenAds family are often distributed as popular and harmless applications... The trojans were concealed in a number of tools for optimizing the operation of Android devices, and were distributed under the guise of messengers, multimedia, and other software.

Command and Control

3 techniques
T1071.001Web ProtocolsEvidence1

Using Android.Phantom trojans, cybercriminals manipulate ad clicks on websites with the help of both machine-learning technologies and WebRTC... The clickers download the required behavioral model from a remote server as well as JavaScript containing the framework itself

T1105Ingress Tool TransferEvidence1

The clickers download the required behavioral model from a remote server as well as JavaScript containing the framework itself and all of the functions necessary for the model to operate

T1219Remote Access ToolsEvidence1

If a device supports WebRTC, Android.Phantom clickers broadcast a virtual screen with the loaded website to the attackers, who then control the website manually or using an automated system.

Impact

1 technique
T1496Resource HijackingEvidence1

In January 2026, our anti-virus laboratory informed users about the Android.Phantom trojan clickers. These malicious programs use machine learning and video broadcasts to boost clicks on websites.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.