HUMAN's Satori Threat Intelligence and Research Team disclosed an Android ad fraud and malvertising operation dubbed Trapdoor that relied on 455 malicious apps and 183 threat actor-controlled command-and-control domains. The apps were disguised as common utilities such as PDF readers, file managers, and device cleanup tools, then prompted users to install fake software updates or secondary apps. Those follow-on payloads used hidden embedded browsers and WebViews to load malicious HTML5 content in the background, generating fraudulent ad impressions, clicks, and bid requests without the victim's knowledge.
Researchers said the scheme was effectively self-funding, turning seemingly legitimate installs into an illicit advertising revenue loop that financed further malvertising. At its peak, Trapdoor generated up to 659 million bid requests per day and was tied to more than 24 million fraudulent app installs. The malware also used install attribution services and download-origin checks to activate malicious behavior mainly for users acquired through the actors' own ad campaigns while suppressing activity for organic installs, helping it evade detection. Most observed traffic came from the United States, with additional activity seen in Japan, Australia, Russia, New Zealand, India, and elsewhere; after responsible disclosure, Google removed the identified apps from Google Play.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
HUMAN researchers publicly reported the Trapdoor Android ad fraud and malvertising scheme, detailing its use of utility-themed apps, fake software updates, selective activation via install attribution abuse, and global traffic footprint. Multiple outlets reported the disclosure on May 19, 2026.
After responsible disclosure by HUMAN's Satori Threat Intelligence and Research Team, Google removed the identified malicious Android apps from the Google Play Store. The takedown disrupted the Trapdoor ad fraud and malvertising operation.
The Trapdoor operation used 455 malicious Android apps and 183 threat actor-controlled command-and-control domains, disguising apps as benign utilities and pushing fake updates that delivered a second-stage payload. The malware used hidden embedded browsers and HTML5 content to generate fraudulent ad impressions, clicks, and bid requests, reaching up to 659 million daily bid requests and more than 24 million app installs, with most traffic observed in the United States.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
zimperium.com
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourcetechradar.com
Open sourcethehackernews.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehumansecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.