Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Home/Threats/MagicAd Android Malware Bypasses Restrictions, Floods Devices with Ads
Threats

MagicAd Android Malware Bypasses Restrictions, Floods Devices with Ads

Key Takeaways A new Android trojan, “MagicAd,” is aggressively pushing unwanted advertisements onto devices, circumventing standard operating system security measures. The malware was...

Jennifer sherman
Jennifer sherman
June 9, 2026 4 Min Read
55 0

Key Takeaways

  • A new Android trojan, “MagicAd,” is aggressively pushing unwanted advertisements onto devices, circumventing standard operating system security measures.
  • The malware was distributed through over 50 malicious applications on Xiaomi’s GetApps store and also appeared on the Samsung Galaxy Store.
  • MagicAd employs sophisticated evasion techniques, including abusing legitimate system components and media controls, to ensure persistent ad delivery even after the host app is closed.
  • While new infected app distribution has ceased, devices already compromised remain vulnerable.

A sophisticated new Android trojan, dubbed MagicAd, has been identified for its ability to bypass the operating system’s native restrictions, flooding infected devices with persistent advertisements. This advanced adware leverages multiple covert techniques to ensure its ad delivery mechanisms remain active in the background, even after users explicitly close the infected applications.

Table Of Content

  • Key Takeaways
  • Widespread Distribution and Evasion
  • Technical Bypass Mechanisms
  • What You Should Do

Security researchers detailed MagicAd’s tactics in a recent report, highlighting its unique persistence and evasion capabilities. The malware’s primary objective is to display advertisements, but its method of doing so demonstrates a notable level of ingenuity in circumventing Android’s protective measures.

Widespread Distribution and Evasion

MagicAd initially spread through more than 50 games and applications hosted on GetApps, the official application store for Xiaomi devices. The threat actors behind MagicAd employed a dynamic strategy, frequently uploading new infected apps that would remain available for approximately one month before being removed and replaced. This rotational approach was likely designed to evade detection by app store security teams, while ensuring that the malware persisted on users’ devices long after the initial malicious app was delisted.

Dr.Web, a cybersecurity firm, reported that MagicAd first emerged in 2025 and was also observed on the Samsung Galaxy Store around the same period. Crucially, once an infected app is installed, its malicious payload continues to operate regardless of whether the original application is removed from the app store. While the developers have reportedly ceased distributing new compromised uploads, devices already infected remain at risk of ongoing ad bombardment.

Before initiating its ad-serving activities, MagicAd incorporates anti-analysis checks. It actively scans for virtual machine environments, verifies that the installation originated from a genuine user interaction, and cross-references the device’s network address against an internal blacklist. If these checks pass, the trojan then hides its icon from the device’s app menu and establishes silent background services, ensuring continuous operation.

The malware’s impact extends beyond Xiaomi devices, with variants engineered to target Vivo smartphones and Amazon Fire TV devices, indicating a broader malicious campaign.

Technical Bypass Mechanisms

MagicAd’s core innovation lies in its ability to display advertisements without requesting the “draw over other apps” permission, which is typically required for such overlay functionalities. Instead, it renders advertising banners as a “Translucent Activity,” allowing them to appear on screen without triggering the standard permission prompts or user consent.

On Xiaomi devices, the trojan exploits inter-app communication by sending specially crafted messages, known as intents, to trusted built-in system applications like Mi Browser and Miui SystemUI. These legitimate system components, designed to receive instructions even when not actively open, are then manipulated by MagicAd to relay and push advertisements onto the display. Similarly, on Vivo devices, the malware utilizes the lower-level Android Binder system channel, targeting applications such as iManager, Phonebook, Vivo Browser, and Baidu IME Customized to achieve the same ad injection.

Examples of ads displayed by Android.MagicAd.1 (Source - Dr.Web)
Examples of ads displayed by Android.MagicAd.1 (Source – Dr.Web)

Perhaps its most ingenious method, which functions across a wide range of Android devices irrespective of the manufacturer, involves manipulating the system’s media controls. MagicAd decrypts a concealed audio file embedded within its own code, then launches the system’s media player at an inaudible zero volume. It links this media playback to Android’s global media controls and subsequently simulates a button press via a background command. This action transfers control back to the malware, enabling it to silently launch an advertisement, which appears to the user without any discernible trigger.

What You Should Do

  • Review Installed Apps: Regularly audit your device for unfamiliar or suspicious applications. Uninstall any apps you do not recognize or that exhibit unexpected behavior.
  • Keep OS Updated: Ensure your Android operating system is always updated to the latest version. Newer OS iterations often include enhanced security features that mitigate the types of background activity MagicAd exploits.
  • Use Mobile Security Software: Install a reputable mobile security solution capable of detecting and removing adware and trojans. These tools can identify malicious background processes and protect against infections.
  • Exercise Caution with Downloads: Be wary of downloading applications from unofficial or less-known app stores. Even official stores can sometimes host malicious apps, so always check app reviews and developer legitimacy.
  • Monitor Permissions: Periodically review the permissions granted to your installed applications, especially those related to drawing over other apps or background services, and revoke any that seem excessive or unnecessary.

Indicators of Compromise (IoCs):-

Type Indicator Description
Malware Name Android.MagicAd.1 Primary trojan variant distributing background ads report
Malware Name Android.MagicAd.1.origin Dex component module used to relay and launch advertisements <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/6682f9bc-ffd7-4792-ae48-10a400b3329f/New-MagicAd-Android-Malware-Flood-Device-With-Ads-Bypassing-Restrictions.pdf?AWSAccessKeyId=ASIA2F3EMEYET6CWNH5Z&Signature=sEeYN7uNKjREeEqv39c3a4mS8OM%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEAgaCXVzLWVhc3QtMSJIMEYCIQC9izHvtaJIAyTgJys1zEKJGV9D2y9rO68%2Bf6XMqjUt2gIhAM2K8hJ%2FQBLLzZiXNkDh5EflSdi71sylrYlXX%2F0kxmIOKvwECNH%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1Igxjedz62fT7GirJZ0oq0ATj9dQRlAlc1zzpnuzZvzbEpPIQippXE0BqWjHOSqPRwdzDfn8rJAanE7ixIPugyXwYeRQYoNyHS2ZzmmpalXVTkQT%2BrAowCilQxnfW%2FXxIj1dQYbvhnPXol9gyl8vedxJXLlPiPn4roKcAzW86B7J73Zl2iur8SO0dXMpN66dSvZ0kMJxsnACEb0P%2BorJzE7FhMt5p64O0kB%2BfhNugbd9Dl%2BIutJJDEMh2YcKQxeiOxpQvmR9zRbOmcq5izd8v1UEJ94RsSRgcDrBGVgTmiiZl%2FemQb6i9N%2BuPO7ij%2Fa9Gus%2FfshO7JrlCSe9V%2FNhDc%2B5txns8Hb4dGUUAtY0RWDxagoALyX%2FjaLBCgCBLBeXAKSdKDfKjmE3d1Qb2upnXkYxMQpopmwyxC%2Fta10yIZ2GSp4gKB3bK0kDUTxMbeeAQGNjJ78Msl9McAe1iJvRpjRi9bwvZw0gWA3oSqDRH0vedbRa8ar5oykf6plt2%2BzwCsHPgNXgKoKYe0eqRcuTaclRrucUbpxBnTnGYzgmsLGiJHksdBX2WV14RRFLy60sSUzEJ1iQ5B2C3qgOisjBHypeH3AoW6Hwd4%2Fg8udfYlkqOI2JoYb%2F%2F945cFyaCzH63y1NhCIjTeLcN%2BhumgRWTvTZwZZbKsRNTZWdBS%2F4BLud3iAsn%2BMfkKMcm0XkuvYHze9%2BVhyaQ6UZS2gJF%2FlnAX0nhi

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

MalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Browser-in-the-Browser Phishing Steals Microsoft 365 Logins

Next Post

Critical Windows Defender Zero-Day Lets Attackers Gain SYSTEM Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us