Threat reportMalwareTL-2026-0737
Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled Vivo / Amazon Fire TV Apps
Android.MagicAd Trojan Floods Devices with Ads via Xiaomi (TL-2026-0737), also tracked as Android.MagicAd.1, is a medium-severity malware campaign, first published 2026-06-09. It has no confirmed attribution, affects Xiaomi GetApps app store (Android) / MIUI devices, maps to 20 MITRE ATT&CK techniques (T1406.001, T1406.002, T1407), and is covered by 9 detection rules and 22 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-0737
- Threat ID
- TL-2026-0737
- Also known as
- Android.MagicAd.1, Android.MagicAd.1.origin, MagicAd
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- consumer, retail, media, telecommunications
- Target regions
- Global, Asia, Europe, North America
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Android.MagicAd Trojan Floods Devices with Ads via Xiaomi
Malware and tooling: Android.MagicAd, Android.MagicAd.1, Android.MagicAd.1.origin
How Android.MagicAd Trojan Floods Devices with Ads via Xiaomi works
Android.MagicAd is an in-the-wild Android adware trojan that floods infected devices with persistent background advertisements while bypassing Android's overlay-permission and analysis-resistance controls. Doctor Web found it embedded in 50+ games and apps on Xiaomi's GetApps store and the Samsung Galaxy Store, in third-party APK mods on Apkmody/Moddroid, and as variants targeting Vivo smartphones and Amazon Fire TV devices, with infected titles rotated roughly monthly to evade detection.
Android.MagicAd (Doctor Web detections Android.MagicAd.1 and its dex component Android.MagicAd.1.origin) is a mobile adware/ad-fraud trojan first observed in the wild in 2025 and detailed in Doctor Web's Q1 2026 mobile virus-activity review. Its primary objective is monetization through aggressive, unsolicited advertising rather than data theft, but its evasion and persistence engineering make it notable as a widely distributed mobile threat warranting dedicated detection coverage.
Distribution is multi-channel and abuses trusted supply chains. Doctor Web found MagicAd concealed in more than 50 games and programs on Xiaomi's official GetApps catalog, with additional variants on the Samsung Galaxy Store. The operators rotated their uploads: an infected app typically remained available for roughly one month before being pulled and replaced with a freshly uploaded title, a tactic that both extends campaign lifetime and frustrates signature-based takedowns. The trojans were also pushed through third-party APK sites such as Apkmody and Moddroid, frequently masquerading as modified ('mod') builds of popular services. Beyond app-store delivery, MagicAd appeared as device-specific variants on Vivo smartphones and Amazon Fire TV devices, indicating compromise or abuse of preinstalled/system-app channels on those platforms.
Part of MagicAd's malicious functionality is hidden inside encrypted native libraries stored in the app's resource directory. At runtime the trojan decrypts these libraries, extracts dex components from them, and executes the embedded modules — keeping the malicious logic out of static view of store-vetting and many scanners. Before displaying any ads, MagicAd performs environment-safety checks: it searches for virtual-machine / emulator artifacts, verifies whether the installation appears 'organic' (a real user install rather than an automated/analysis install), and filters the device's IP address against a blacklist, suppressing activity in suspected analysis environments.
MagicAd's defining trait is displaying advertisements without requesting the SYSTEM_ALERT_WINDOW permission that normally gates screen overlays. Instead it renders ad banners as Translucent Activity windows, which surface on screen without triggering the usual overlay-permission checks. To reach and wake system surfaces, it sends crafted Intents (including pending intents) to built-in apps that process intents even when not explicitly launched: on Xiaomi devices it targets Mi Browser and the MIUI SystemUI shell; on Amazon devices it leverages the Fire TV Home Screen launcher; on Vivo devices it uses the lower-level Android Binder channel against iManager, Phonebook, Vivo Browser, and a customized Baidu IME. A platform-agnostic fallback decrypts an audio file embedded in the trojan's body, writes it to its working directory, launches the system media player at zero volume, and simulates button presses to silently trigger ad playback/interaction.
For persistence the trojan hides its launcher icon from the app menu, spawns multiple silent background/foreground services backed by notification channels, and registers task-scheduler 'watchdog' jobs that periodically restart its services. On older Android versions it can launch a virtual screen to keep itself alive and prevent the system from shutting it down. Multiple fallback methods with retry logic ensure the ad-delivery and persistence loops continue even after the originating app is removed from a store. Defenders should treat MagicAd primarily as an ad-fraud / resource-abuse and trust-erosion threat on Android, Vivo, and Fire TV estates and prioritize behavioral detection (icon hiding, translucent-activity ad rendering, runtime dex loading from encrypted native libs, watchdog re-spawn, and intent abuse against system apps).
MITRE ATT&CK techniques used in TL-2026-0737
Defense Evasion
T1406.001 Steganography; T1406.002 Software Packing; T1628.001 Suppress Application Icon; T1628.002 User Evasion; T1633.001 System Checks; T1655.001 Match Legitimate Name or Location
defense-evasion
T1407 Download New Code at Runtime
Discovery
T1418 Software Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery
Command and Control
Initial Access
T1474.002 Compromise Hardware Supply Chain; T1474.003 Compromise Software Supply Chain; T1660 Phishing
Impact
T1516 Input Injection; T1643 Generate Traffic from Victim
Persistence
T1541 Foreground Persistence; T1603 Scheduled Task/Job; T1624.001 Broadcast Receivers
Execution
Affected products and versions in Android.MagicAd Trojan Floods Devices with Ads via Xiaomi
- Xiaomi — GetApps app store (Android) / MIUI devices
Vulnerable versions: 50+ trojanized games and apps distributed via GetApps - Samsung — Galaxy Store (Android)
Vulnerable versions: Android.MagicAd variants distributed via Galaxy Store - Vivo — Vivo smartphones (preinstalled/system-app variant)
Vulnerable versions: Variant abusing iManager, Phonebook, Vivo Browser, Baidu IME Customized via Binder - Amazon — Fire TV devices
Vulnerable versions: Variant abusing Fire TV Home Screen launcher
Remediation for Android.MagicAd Trojan Floods Devices with Ads via Xiaomi
Immediate actions
- Uninstall apps flagged as Android.MagicAd.1 / Android.MagicAd.1.origin and any recently installed games or modified 'pro/plus' app builds that hide their icon or show out-of-context full-screen ads
- Block and remove sideloaded APKs sourced from third-party sites such as Apkmody and Moddroid via MDM policy
- On managed Android/Vivo/Fire TV fleets, audit for apps spawning persistent background services with hidden launcher icons
Workarounds
- Disable sideloading / unknown-sources installation
- Review and revoke ability of non-system apps to launch foreground services and schedule background tasks where MDM allows
- Remove preinstalled bloat/system apps that are abused as ad-surface targets where the platform permits
Longer-term hardening
- Deploy a reputable mobile EDR/AV with behavioral detection for runtime dex loading, translucent-activity ad rendering, and icon hiding
- Restrict installs to vetted enterprise app catalogs and disable installation from unknown sources via MDM
- Enable Google Play Protect and keep it on; monitor for re-uploaded clones of removed titles
- Educate users not to install 'modded' versions of Spotify, YouTube, Deezer, Netflix and similar apps
Weaknesses (CWE) in Android.MagicAd Trojan Floods Devices with Ads via Xiaomi
Timeline of Android.MagicAd Trojan Floods Devices with Ads via Xiaomi
- Android.MagicAd first appears in the wild, distributed through legitimate and third-party Android app sources (Doctor Web, year-of-first-observation per Q1 2026 review).
- Android.MagicAd embedded in more than 50 games and programs on Xiaomi's official GetApps catalog, with infected titles rotated roughly monthly to evade takedown.
- Variants identified on the Samsung Galaxy Store and distributed via third-party APK sites Apkmody and Moddroid as modified versions of popular apps.
- Device-specific variants observed targeting Vivo smartphones (abusing iManager, Phonebook, Vivo Browser, Baidu IME via Binder) and Amazon Fire TV devices (abusing the Fire TV Home Screen launcher).
- Public reporting (The420 and others) highlights Dr.Web findings on Android ad-fraud trojans abusing Xiaomi GetApps.
- Doctor Web documents Android.MagicAd in its Q1 2026 mobile virus-activity review, detailing translucent-activity ad rendering, encrypted native-library dex loading, and watchdog persistence.
- Doctor Web releases Android.MagicAd indicators of compromise via its public malware-iocs GitHub repository (github.com/DoctorWebLtd/malware-iocs) for defender consumption.
- Doctor Web publishes its dedicated Android.MagicAd advisory (news.drweb.com/show/?i=15262) describing per-device ad-display techniques, SYSTEM_ALERT_WINDOW bypass, system media-player abuse, and the abuse of built-in apps (Mi Browser, MIUI SystemUI, Fire TV launcher, Vivo iManager/Phonebook/Browser/Baidu IME).
- Wider security press (Cyber Security News, GBHackers) publish detailed analyses of Android.MagicAd; threat tracked as ACTIVE.
Sources cited for Android.MagicAd Trojan Floods Devices with Ads via Xiaomi
- New MagicAd Android Malware Floods Devices with Ads
- Android.MagicAd trojan displays ads despite all restrictions
- MagicAd Android Malware Bypasses Restrictions to Flood Devices With Ads
- Doctor Web's Q1 2026 review of virus activity on mobile devices
- Android.MagicAd.1 — Dr.Web Malware description library
- Mobile Malware Turns Android Phones Into Silent Engines of Ad Fraud (The420)
- MITRE ATT&CK for Mobile — Hide Artifacts: Suppress Application Icon (T1628.001)
- Doctor Web malware-iocs repository (Android.MagicAd IOCs)
Detection coverage for TL-2026-0737
As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0737 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.