4 Sources
[1]
New Android malware uses AI to click on hidden browser ads
A new family of Android click-fraud trojans leverages TensorFlow machine learning models to automatically detect and interact with specific advertisement elements. The mechanism relies on visual analysis based on machine learning instead of predefined JavaScript click routines, and does not
[2]
Beware: New Android malware uses AI to sneakily commit ad fraud on your phone
The malware is found on certain games distributed through inappropriate app stores, but some have also been found in Xiaomi's GetApps app store. AI is designed to make our lives easier, but it's also adept at making them more difficult. AI-powered tools are becoming increasingly popular among
[3]
Watch out - this devious new Android malware clicks on hidden browser ads to put you at risk
* Android trojans use TensorFlow AI to mimic human ad clicks for fraud * Fake apps on GetApps and other platforms spread malware with hidden browsers * At least six apps found, totaling over 155,000 downloads Cybercriminals have apparently found a way to use Artificial Intelligence (AI) for ad
[4]
This Android Malware Uses AI to Secretly Perform Ad Fraud on Your Phone
Hidden browser mode lets malware run ad fraud in the background Android users are being warned about a new and more advanced form of mobile malware that quietly uses machine learning technology to generate ad clicks in the background. Unlike earlier threats that relied on predictable scripts, this
Share
Copy Link
Security researchers have uncovered a sophisticated Android malware strain that uses Google's TensorFlow machine learning library to automate ad clicks in hidden browsers. The malware affects over 155,000 downloads across games distributed through Xiaomi's GetApps store and third-party platforms, operating covertly while draining batteries and inflating mobile data charges.
A new family of clickjacking trojans is using artificial intelligence to execute AI ad fraud on Android devices, marking a significant shift in how cybercriminals approach mobile threats. Security researchers at Dr. Web have identified malware that leverages TensorFlow.js, Google's open-source library for training and deploying machine learning models in JavaScript, to automatically detect and interact with advertisement elements
1
. Unlike traditional click fraud schemes that rely on predefined JavaScript routines, this Android malware uses visual analysis powered by machine learning models to identify clickable ad elements, making it far more resilient against modern ad variability and behavioral detection systems3
.
Source: Android Authority
The malware operates through two distinct modes that enable AI powered click fraud at scale. In phantom mode, the malware uses a covert WebView browser to load target pages on a virtual screen, where screenshots are continuously captured and analyzed by TensorFlow to identify relevant UI elements
1
. By mimicking human ad clicks through tapping on the correct elements, the malware successfully evades traditional behavior-based defenses that flag automated clicking patterns. When automated interactions fail, the malware switches to signalling mode, which uses WebRTC technology to stream live video feeds of the virtual browser screen directly to attackers, allowing them to perform real-time actions like scrolling, tapping, and entering text2
.The cybersecurity threat has spread primarily through GetApps, Xiaomi's official app store for its devices, where threat actors initially submit clean applications before introducing malicious components in subsequent updates
1
. Dr. Web researchers identified at least six infected games with over 155,000 cumulative downloads, including Theft Auto Mafia with 61,000 downloads, Cute Pet House with 34,000 downloads, and Creation Magic World with 32,000 downloads. All infected apps on GetApps are attributed to a single developer, Shenzhen Ruiren Network Co. Ltd2
.
Source: BleepingComputer
Beyond GetApps, the malware has proliferated across third-party platforms including Moddroid and Apkmody, where researchers found that most apps on Moddroid's "Editor's Choice" page are infected
1
. The trojans are also distributed through Telegram channels and Discord servers, with modified versions of popular applications like Spotify, YouTube, Deezer, and Netflix being weaponized to deliver the malware. One Discord server pushing an infected app called Spotify X had amassed 24,000 subscribers1
.Related Stories
While malware clicks hidden ads without posing an immediate data theft risk, the impact on users manifests through increased battery drainage, premature device degradation, and elevated mobile data consumption
1
. Because the click fraud executes covertly in a hidden WebView rendering content on a virtual screen, victims see no visible indication of malicious activity, especially since many infected apps retain their core functionality1
. This operational stealth reduces user suspicion and allows the malware to operate undetected for extended periods.
Source: TechRadar
Security experts warn that while clickjacking primarily targets ad networks and advertisers for financial gain, the remote hijacking capabilities demonstrated by the signalling mode could potentially be repurposed for more severe attacks, including data theft or targeting other users with infected APK files
2
. The use of TensorFlow to adapt to dynamic ad formats that frequently change structure and often use iframes or video represents a concerning evolution in mobile threats1
. Users are strongly advised to avoid installing apps outside Google Play, enable Google Play Protect, regularly audit app permissions, and remain vigilant about downloading alternative versions of popular apps that promise extra features or free access to premium subscriptions4
.Summarized by
Navi
[1]
[2]
[3]