MagicAd Android Malware Bypasses Restrictions, Floods Devices with Ads
Key Takeaways A new Android trojan, “MagicAd,” is aggressively pushing unwanted advertisements onto devices, circumventing standard operating system security measures. The malware was...
Key Takeaways
- A new Android trojan, “MagicAd,” is aggressively pushing unwanted advertisements onto devices, circumventing standard operating system security measures.
- The malware was distributed through over 50 malicious applications on Xiaomi’s GetApps store and also appeared on the Samsung Galaxy Store.
- MagicAd employs sophisticated evasion techniques, including abusing legitimate system components and media controls, to ensure persistent ad delivery even after the host app is closed.
- While new infected app distribution has ceased, devices already compromised remain vulnerable.
A sophisticated new Android trojan, dubbed MagicAd, has been identified for its ability to bypass the operating system’s native restrictions, flooding infected devices with persistent advertisements. This advanced adware leverages multiple covert techniques to ensure its ad delivery mechanisms remain active in the background, even after users explicitly close the infected applications.
Table Of Content
Security researchers detailed MagicAd’s tactics in a recent report, highlighting its unique persistence and evasion capabilities. The malware’s primary objective is to display advertisements, but its method of doing so demonstrates a notable level of ingenuity in circumventing Android’s protective measures.
Widespread Distribution and Evasion
MagicAd initially spread through more than 50 games and applications hosted on GetApps, the official application store for Xiaomi devices. The threat actors behind MagicAd employed a dynamic strategy, frequently uploading new infected apps that would remain available for approximately one month before being removed and replaced. This rotational approach was likely designed to evade detection by app store security teams, while ensuring that the malware persisted on users’ devices long after the initial malicious app was delisted.
Dr.Web, a cybersecurity firm, reported that MagicAd first emerged in 2025 and was also observed on the Samsung Galaxy Store around the same period. Crucially, once an infected app is installed, its malicious payload continues to operate regardless of whether the original application is removed from the app store. While the developers have reportedly ceased distributing new compromised uploads, devices already infected remain at risk of ongoing ad bombardment.
Before initiating its ad-serving activities, MagicAd incorporates anti-analysis checks. It actively scans for virtual machine environments, verifies that the installation originated from a genuine user interaction, and cross-references the device’s network address against an internal blacklist. If these checks pass, the trojan then hides its icon from the device’s app menu and establishes silent background services, ensuring continuous operation.
The malware’s impact extends beyond Xiaomi devices, with variants engineered to target Vivo smartphones and Amazon Fire TV devices, indicating a broader malicious campaign.
Technical Bypass Mechanisms
MagicAd’s core innovation lies in its ability to display advertisements without requesting the “draw over other apps” permission, which is typically required for such overlay functionalities. Instead, it renders advertising banners as a “Translucent Activity,” allowing them to appear on screen without triggering the standard permission prompts or user consent.
On Xiaomi devices, the trojan exploits inter-app communication by sending specially crafted messages, known as intents, to trusted built-in system applications like Mi Browser and Miui SystemUI. These legitimate system components, designed to receive instructions even when not actively open, are then manipulated by MagicAd to relay and push advertisements onto the display. Similarly, on Vivo devices, the malware utilizes the lower-level Android Binder system channel, targeting applications such as iManager, Phonebook, Vivo Browser, and Baidu IME Customized to achieve the same ad injection.

Perhaps its most ingenious method, which functions across a wide range of Android devices irrespective of the manufacturer, involves manipulating the system’s media controls. MagicAd decrypts a concealed audio file embedded within its own code, then launches the system’s media player at an inaudible zero volume. It links this media playback to Android’s global media controls and subsequently simulates a button press via a background command. This action transfers control back to the malware, enabling it to silently launch an advertisement, which appears to the user without any discernible trigger.
What You Should Do
- Review Installed Apps: Regularly audit your device for unfamiliar or suspicious applications. Uninstall any apps you do not recognize or that exhibit unexpected behavior.
- Keep OS Updated: Ensure your Android operating system is always updated to the latest version. Newer OS iterations often include enhanced security features that mitigate the types of background activity MagicAd exploits.
- Use Mobile Security Software: Install a reputable mobile security solution capable of detecting and removing adware and trojans. These tools can identify malicious background processes and protect against infections.
- Exercise Caution with Downloads: Be wary of downloading applications from unofficial or less-known app stores. Even official stores can sometimes host malicious apps, so always check app reviews and developer legitimacy.
- Monitor Permissions: Periodically review the permissions granted to your installed applications, especially those related to drawing over other apps or background services, and revoke any that seem excessive or unnecessary.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Malware Name | Android.MagicAd.1 | Primary trojan variant distributing background ads report |
| Malware Name | Android.MagicAd.1.origin | Dex component module used to relay and launch advertisements <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/6682f9bc-ffd7-4792-ae48-10a400b3329f/New-MagicAd-Android-Malware-Flood-Device-With-Ads-Bypassing-Restrictions.pdf?AWSAccessKeyId=ASIA2F3EMEYET6CWNH5Z&Signature=sEeYN7uNKjREeEqv39c3a4mS8OM%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEAgaCXVzLWVhc3QtMSJIMEYCIQC9izHvtaJIAyTgJys1zEKJGV9D2y9rO68%2Bf6XMqjUt2gIhAM2K8hJ%2FQBLLzZiXNkDh5EflSdi71sylrYlXX%2F0kxmIOKvwECNH%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1Igxjedz62fT7GirJZ0oq0ATj9dQRlAlc1zzpnuzZvzbEpPIQippXE0BqWjHOSqPRwdzDfn8rJAanE7ixIPugyXwYeRQYoNyHS2ZzmmpalXVTkQT%2BrAowCilQxnfW%2FXxIj1dQYbvhnPXol9gyl8vedxJXLlPiPn4roKcAzW86B7J73Zl2iur8SO0dXMpN66dSvZ0kMJxsnACEb0P%2BorJzE7FhMt5p64O0kB%2BfhNugbd9Dl%2BIutJJDEMh2YcKQxeiOxpQvmR9zRbOmcq5izd8v1UEJ94RsSRgcDrBGVgTmiiZl%2FemQb6i9N%2BuPO7ij%2Fa9Gus%2FfshO7JrlCSe9V%2FNhDc%2B5txns8Hb4dGUUAtY0RWDxagoALyX%2FjaLBCgCBLBeXAKSdKDfKjmE3d1Qb2upnXkYxMQpopmwyxC%2Fta10yIZ2GSp4gKB3bK0kDUTxMbeeAQGNjJ78Msl9McAe1iJvRpjRi9bwvZw0gWA3oSqDRH0vedbRa8ar5oykf6plt2%2BzwCsHPgNXgKoKYe0eqRcuTaclRrucUbpxBnTnGYzgmsLGiJHksdBX2WV14RRFLy60sSUzEJ1iQ5B2C3qgOisjBHypeH3AoW6Hwd4%2Fg8udfYlkqOI2JoYb%2F%2F945cFyaCzH63y1NhCIjTeLcN%2BhumgRWTvTZwZZbKsRNTZWdBS%2F4BLud3iAsn%2BMfkKMcm0XkuvYHze9%2BVhyaQ6UZS2gJF%2FlnAX0nhi
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.