Researchers reported that monetized URL shortener services and fake download pages were used to push Android/FakeAdBlocker and other malicious Android apps disguised as ad blockers or popular applications. Victims were funneled through aggressive advertising chains and prompted to install APKs with misleading names such as adBLOCK app.apk, after which the malware hid its icon, contacted command-and-control infrastructure, and fetched additional payloads. ESET said the campaign generated more than 150,000 Android downloads in the first half of 2021, while iPhone users were steered into fraudulent calendar-subscription scams rather than direct malware installs.
The Android infections did not stop at adware. Researchers said the delivery chains also deployed banking trojans including Cerberus, Ginp, and TeaBot, alongside SMS trojans and other payloads, making the outcome dependent on the victim's region and the operators' current configuration. Separate reporting on Cerberus and Ginp described both as mobile banking malware families, and Bitdefender documented similar lures using mockups of well-known apps to spread TeaBot and FluBot, underscoring a broader ecosystem in which deceptive mobile install flows are used to distribute credential theft, financial fraud, and messaging abuse malware on Android.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
ESET published detailed research describing how monetized URL shortener services were used to distribute Android/FakeAdBlocker, adware, banking trojans, SMS trojans, and iOS calendar-subscription scams. The report also documented the malware's payload delivery, regional targeting, and abuse of Google Calendar for scareware.
ESET said it detected more than 150,000 downloads of Android/FakeAdBlocker to Android devices between the beginning of 2021 and July 1, 2021. The figure indicates substantial campaign scale during that period.
Bitdefender Labs identified TeaBot, also known as Anatsa, as another banking trojan delivered by Android/FakeAdBlocker. This added another banking malware family to the list of observed payloads.
ThreatFabric published research on Ginp, another Android banking trojan. ESET later identified Ginp as one of the payloads distributed through the Android/FakeAdBlocker campaign.
ESET reported that the Android/FakeAdBlocker malware family was first spotted in September 2019. The campaign used monetized URL shortener services and deceptive download flows to target mobile users.
ThreatFabric published research on Cerberus as a new Android banking trojan. This establishes Cerberus as an existing malware payload later delivered by Android/FakeAdBlocker.
4 references tracked. Mallory keeps watching after this page renders.
labs.bitdefender.com
Open sourcewelivesecurity.com
Open sourcethreatfabric.com
Open sourcethreatfabric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.