惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
D
Docker
量子位
A
Arctic Wolf
GbyAI
GbyAI
F
Full Disclosure
J
Java Code Geeks
D
Darknet – Hacking Tools, Hacker News & Cyber Security
W
WeLiveSecurity
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
U
Unit 42
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
S
Secure Thoughts
T
Tor Project blog
M
MIT News - Artificial intelligence
腾讯CDC
E
Exploit-DB.com RSS Feed
Y
Y Combinator Blog
PCI Perspectives
PCI Perspectives
C
CERT Recently Published Vulnerability Notes
B
Blog
P
Proofpoint News Feed
www.infosecurity-magazine.com
www.infosecurity-magazine.com
S
Schneier on Security
T
Threat Research - Cisco Blogs
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
SegmentFault 最新的问题
Know Your Adversary
Know Your Adversary
Last Week in AI
Last Week in AI
Hacker News: Ask HN
Hacker News: Ask HN
G
GRAHAM CLULEY
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Blog — PlanetScale
Blog — PlanetScale
S
Security Archives - TechRepublic
酷 壳 – CoolShell
酷 壳 – CoolShell
Latest news
Latest news
V
Vulnerabilities – Threatpost
Security Latest
Security Latest
G
Google Developers Blog
云风的 BLOG
云风的 BLOG
博客园 - 聂微东
T
Tenable Blog
博客园 - 叶小钗
The GitHub Blog
The GitHub Blog
宝玉的分享
宝玉的分享
N
Netflix TechBlog - Medium
B
Blog RSS Feed
P
Privacy International News Feed
AWS News Blog
AWS News Blog

Hackread – Cybersecurity News, Data Breaches, AI and More

Hackers Hide New Argamal Malware Inside Working Hentai Games Extradited Ukrainian Man Admits Role in Conti Ransomware Attacks Atomic Arch Campaign Hijacks 20+ Linux AUR Packages to Deliver Malware ShinyHunters Target Universities in Oracle PeopleSoft Zero-Day Attack The SpaceX Pre-IPO Market: How Crypto Rails Are Opening Synthetic Access Feds Seize AudiA6 and Dark2Web in $389M Crypto Laundering Case ShinyHunters Leak 40GB of University of Nottingham Student Data Authorities Dismantle Decade-Old SniperDZ Phishing Network Criminal IP at Infosecurity Europe 2026: Introducing AITEM, the Next Chapter of Attack Surface Management Hackers Use Fake Claude Code Guide and AI PDFs to Spread AsyncRAT Malware The Hidden Security Risks of Poor Software Testing FBI Seizes China-Linked Fake Consulting Sites Targeting US Clearance Holders How to Turn Images into Animated Videos with AI: A Wondershare Filmora Guide Scammers Use TikTok and Instagram Reels to Spread Vidar Infostealer ServiceNow Discloses Security Incident Exposing Customer Data Cloud Security Report Finds Fragmented Tools Widening the Cloud Complexity Gap Microsoft June 2026 Patch Tuesday Fixes 206 Flaws and 3 Zero-Days Network Log Analysis: Why Collecting Logs is Not Enough E-Signature Security Checklist Before Selecting an E-Signature Tool Maine Govt Portal Lists 10M Discord Data Breach Notice, But Filing Shows Red Flags Handala Claims Israeli Radar Hack, But Evidence Shows Phone Admin Panel WhatsApp Says It Blocked Pegasus Spyware Campaign Linked to NSO Operation FlutterBridge Uses Fake Google Ads to Spread macOS Backdoor Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware Silent Ransom Group Uses Fast Flux Botnet to Hide Law Firm Leak Sites New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account Atlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service Users Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords iFood Confirms Data Breach Affecting 1.2 Million Users in Brazil Why eSIMs Are Replacing Traditional SIM Cards Lazarus Group Uses npm Brandjacking Campaign to Target Developers Five Eyes Warns Chinese Spies Are Using Fake Job Ads to Target Military Staff How to Recover Data from iCloud Backup Without Resetting Your iPhone China-Linked TA4922 Hackers Target UK, Europe With New SilentRunLoader Malware Alcasec, "Robin Hood of Spanish Hackers," Jailed for 31 Months Over Data Theft Fake ChatGPT Desktop App Ads Used to Push Password-Stealing Malware Hackers Abused Meta’s AI Support Bot to Hijack Major Instagram Accounts New WordPress Malware Uses Steam Profile Comments to Hide C2 Instructions Halo Security Honored with 2026 MSP Today Product of the Year Award Why Encrypted File Sharing Is Essential for Modern Businesses What One Predator Case Can Reveal About an Online Platform’s Safety Gaps RaccoonLine Publishes 2026 dVPN Buyer’s Guide for Privacy-Focused Users How to Get a Reddit API Key in 2026: Step-by-Step Guide Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts How to Get the Most From Your Explainer Video Production Services Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives 27,000-Download Codex UI Tool Secretly Stole OpenAI Refresh Tokens Fake Anthropic Sites Deliver Fileless Infostealer to Claude Code Users The Deliverability Problem: How New Platforms Are Solving Inbox Placement The CISO Whisperer's Watch List For The Gartner Security & Risk Management Summit 2026 Can Big Data Predict Market Movements Accurately? Iran’s Nimbus Manticore Used Trojanized Zoom Installers Against US Firms How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts? Link11 is fully committed to Europe and is opening a Customer Excellence Hub in Lisbon Trojanized Gemini and Claude Installers Target Developers Via SEO Poisoning Claude Mythos AI Identified 10,000+ Software Vulnerabilities in One Month FBI Chief Kash Patel’s Clothing Store Hacked in ClickFix Infostealer Attack Netherlands Busts Bulletproof Hosting Network Linked to Disinfo and Cybercrime
Over 50 Android Apps Found Spreading MagicAd Trojan via Official Stores
Deeba Ahmed · 2026-06-15 · via Hackread – Cybersecurity News, Data Breaches, AI and More

A deceptive trojan is outsmarting Android’s built-in defences to bombard users with unstoppable background advertisements. Security analysts at Doctor Web recently found Android.MagicAd.1, a trojan malware that manipulates legitimate phone systems to force-feed ads even when all app windows are closed.

This is a frustrating trick, proving that ad-delivering threats are no longer just a minor nuisance but highly engineered tools designed to break safety rules.

The Infection Chain

Android.MagicAd.1 first appeared in 2025, but researchers say it is now being pushed through more than 50 infected games and utility apps. The malicious apps were not limited to shady download sites either. They were distributed through official app stores, including Samsung Galaxy Store and Xiaomi’s GetApps catalogue.

Some games and programs from the GetApps catalogue hiding Android.MagicAd.1 (Credit: Doctor Web)

To evade early detection by security scanners, the hackers rotated their apps, keeping them online for less than a month before swapping them with new versions. However, once downloaded, the trojan remained active on user devices.

The attack chain begins with hidden, encrypted components inside native code libraries. When a victim opens a compromised app, the malware decrypts these resources to extract a core component called Android.MagicAd.1.origin.

This Android malware also performs environment checks before launching its payload. It scans for virtual machines or blacklisted IP addresses to ensure it’s not being monitored by security researchers. If everything is clear, it hides its app icon from the home screen menu and schedules background tasks to keep itself running permanently.

Bypassing Android Restrictions

Researchers explained in the blog post that modern Android operating systems strictly forbid background apps from launching themselves or displaying windows over other programs without explicit permissions. Android.MagicAd.1, however, can bypass this barrier simply by targeting trusted, pre-installed system applications. The way it does this depends heavily on the phone’s manufacturer.

On Xiaomi and Amazon devices, the malware sends a delayed system command called a “pending intent” to its internal component, Android.MagicAd.1.origin. It routes this command through standard system apps like Mi Browser, Miui SystemUI, or the Amazon Fire TV Home Screen launcher to wake itself up and draw transparent ad banners right over active screens.

For Vivo devices, the hackers exploit an internal communications system called Android Binder instead, sending data packages through standard tools like iManager, Phonebook, or Vivo Browser to trigger the background ads.

On other brands, the trojan program uses a clever, universal fallback. It saves a silent audio file, opens the system media player at zero volume, and simulates a physical button click using a background command. This trick fools the operating system into giving the trojan immediate priority to display its ads.

Ads displayed by the trojan (Credit: Doctor Web)

Doctor Web confirms that all identified malicious apps have now been removed from official stores. While the immediate distribution loop has been broken, this campaign shows how easily threat actors can weaponize the very software meant to protect us.

(Image by iXimus from Pixabay)