Home Android Android Malware MagicAd Delivers Aggressive Ad Flooding Campaign

Android Malware MagicAd Delivers Aggressive Ad Flooding Campaign

0
MagicAd Malware Floods Android

A stealthy Android Trojan dubbed Android.MagicAd that aggressively floods devices with background advertisements.

The malware employs multiple sophisticated techniques to bypass Android operating system restrictions, including exploiting system apps and manipulating the default media player.

Threat actors initially distributed the malware through official channels, including the Samsung Galaxy Store and Xiaomi’s GetApps application catalog.

To avoid premature detection, the attackers disguised the Trojan within more than 50 different games and utility programs.

These infected apps operated on a short lifecycle, appearing in the storefront for about a month before developers swapped them out for fresh versions.

While these malicious applications have since been removed from the GetApps catalog, the trojan remains active on devices that previously downloaded the compromised software.

MagicAd Malware Floods Android

The developers behind MagicAd invested heavily in evasion tactics to ensure the malware stays on infected devices. The core malicious functionality hides within .dex files tucked away inside encrypted native libraries.

The Trojan decrypts these libraries in real time, extracting and executing their payloads only when it determines the environment is safe.

Examples of games and programs from the GetApps catalog in which Android.MagicAd.1 was concealed. At the time of this news release, these and other trojan modifications were unavailable for download (Source: drweb)

Before launching any advertisements, MagicAd performs a thorough environmental check to avoid analysis by security researchers.

It looks for indicators that it is running in a virtual machine, verifies whether the installation occurred organically, and checks whether the infected device’s IP address appears on its internal blocklist.

To display advertisements while running quietly in the background, MagicAd relies on drawing banners as a “Translucent Activity” over existing windows.

Examples of ads displayed by Android.MagicAd.1 (Source: drweb)

This clever trick allows the malware to overlay ads without ever prompting the user for the standard system alert window permission.

The Trojan then executes specific exploits depending on the manufacturer of the infected device, drweb said.

On Xiaomi and Amazon devices, the malware uses Android Intents to hijack system applications like Mi Browser, Miui SystemUI, and the Amazon Fire TV Home Screen.

Examples of ads displayed by Android.MagicAd.1 (Source: drweb)

Because these are trusted system apps, they can process background commands without direct user interaction.

The malware sends a pending intent to its own hidden module, which then tricks the target system app into waking up the trojan or launching the ad directly.

The threat actors use a slightly different approach for Vivo smartphones. MagicAd exploits the Android Binder, a core system component that manages inter-process communication.

The malware targets Vivo-specific system programs, such as iManager and Vivo Browser. It sends regular intents via Parcel data containers.

This tricks legitimate Vivo applications into launching the Trojan’s advertising component in the background.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version