Threat reportMalwareTL-2026-0737

Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled Vivo / Amazon Fire TV Apps

mediumACTIVE

Android.MagicAd Trojan Floods Devices with Ads via Xiaomi (TL-2026-0737), also tracked as Android.MagicAd.1, is a medium-severity malware campaign, first published 2026-06-09. It has no confirmed attribution, affects Xiaomi GetApps app store (Android) / MIUI devices, maps to 20 MITRE ATT&CK techniques (T1406.001, T1406.002, T1407), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0737

Threat ID
TL-2026-0737
Also known as
Android.MagicAd.1, Android.MagicAd.1.origin, MagicAd
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
consumer, retail, media, telecommunications
Target regions
Global, Asia, Europe, North America
Detection rules
9
Indicators of compromise
22

Malware and tooling in Android.MagicAd Trojan Floods Devices with Ads via Xiaomi

Malware and tooling: Android.MagicAd, Android.MagicAd.1, Android.MagicAd.1.origin

How Android.MagicAd Trojan Floods Devices with Ads via Xiaomi works

Android.MagicAd is an in-the-wild Android adware trojan that floods infected devices with persistent background advertisements while bypassing Android's overlay-permission and analysis-resistance controls. Doctor Web found it embedded in 50+ games and apps on Xiaomi's GetApps store and the Samsung Galaxy Store, in third-party APK mods on Apkmody/Moddroid, and as variants targeting Vivo smartphones and Amazon Fire TV devices, with infected titles rotated roughly monthly to evade detection.

Android.MagicAd (Doctor Web detections Android.MagicAd.1 and its dex component Android.MagicAd.1.origin) is a mobile adware/ad-fraud trojan first observed in the wild in 2025 and detailed in Doctor Web's Q1 2026 mobile virus-activity review. Its primary objective is monetization through aggressive, unsolicited advertising rather than data theft, but its evasion and persistence engineering make it notable as a widely distributed mobile threat warranting dedicated detection coverage.

Distribution is multi-channel and abuses trusted supply chains. Doctor Web found MagicAd concealed in more than 50 games and programs on Xiaomi's official GetApps catalog, with additional variants on the Samsung Galaxy Store. The operators rotated their uploads: an infected app typically remained available for roughly one month before being pulled and replaced with a freshly uploaded title, a tactic that both extends campaign lifetime and frustrates signature-based takedowns. The trojans were also pushed through third-party APK sites such as Apkmody and Moddroid, frequently masquerading as modified ('mod') builds of popular services. Beyond app-store delivery, MagicAd appeared as device-specific variants on Vivo smartphones and Amazon Fire TV devices, indicating compromise or abuse of preinstalled/system-app channels on those platforms.

Part of MagicAd's malicious functionality is hidden inside encrypted native libraries stored in the app's resource directory. At runtime the trojan decrypts these libraries, extracts dex components from them, and executes the embedded modules — keeping the malicious logic out of static view of store-vetting and many scanners. Before displaying any ads, MagicAd performs environment-safety checks: it searches for virtual-machine / emulator artifacts, verifies whether the installation appears 'organic' (a real user install rather than an automated/analysis install), and filters the device's IP address against a blacklist, suppressing activity in suspected analysis environments.

MagicAd's defining trait is displaying advertisements without requesting the SYSTEM_ALERT_WINDOW permission that normally gates screen overlays. Instead it renders ad banners as Translucent Activity windows, which surface on screen without triggering the usual overlay-permission checks. To reach and wake system surfaces, it sends crafted Intents (including pending intents) to built-in apps that process intents even when not explicitly launched: on Xiaomi devices it targets Mi Browser and the MIUI SystemUI shell; on Amazon devices it leverages the Fire TV Home Screen launcher; on Vivo devices it uses the lower-level Android Binder channel against iManager, Phonebook, Vivo Browser, and a customized Baidu IME. A platform-agnostic fallback decrypts an audio file embedded in the trojan's body, writes it to its working directory, launches the system media player at zero volume, and simulates button presses to silently trigger ad playback/interaction.

For persistence the trojan hides its launcher icon from the app menu, spawns multiple silent background/foreground services backed by notification channels, and registers task-scheduler 'watchdog' jobs that periodically restart its services. On older Android versions it can launch a virtual screen to keep itself alive and prevent the system from shutting it down. Multiple fallback methods with retry logic ensure the ad-delivery and persistence loops continue even after the originating app is removed from a store. Defenders should treat MagicAd primarily as an ad-fraud / resource-abuse and trust-erosion threat on Android, Vivo, and Fire TV estates and prioritize behavioral detection (icon hiding, translucent-activity ad rendering, runtime dex loading from encrypted native libs, watchdog re-spawn, and intent abuse against system apps).

MITRE ATT&CK techniques used in TL-2026-0737

Defense Evasion

T1406.001 Steganography; T1406.002 Software Packing; T1628.001 Suppress Application Icon; T1628.002 User Evasion; T1633.001 System Checks; T1655.001 Match Legitimate Name or Location

defense-evasion

T1407 Download New Code at Runtime

Discovery

T1418 Software Discovery; T1422 System Network Configuration Discovery; T1426 System Information Discovery

Command and Control

T1437.001 Web Protocols

Initial Access

T1474.002 Compromise Hardware Supply Chain; T1474.003 Compromise Software Supply Chain; T1660 Phishing

Impact

T1516 Input Injection; T1643 Generate Traffic from Victim

Persistence

T1541 Foreground Persistence; T1603 Scheduled Task/Job; T1624.001 Broadcast Receivers

Execution

T1575 Native API

Affected products and versions in Android.MagicAd Trojan Floods Devices with Ads via Xiaomi

  • Xiaomi — GetApps app store (Android) / MIUI devices
    Vulnerable versions: 50+ trojanized games and apps distributed via GetApps
  • Samsung — Galaxy Store (Android)
    Vulnerable versions: Android.MagicAd variants distributed via Galaxy Store
  • Vivo — Vivo smartphones (preinstalled/system-app variant)
    Vulnerable versions: Variant abusing iManager, Phonebook, Vivo Browser, Baidu IME Customized via Binder
  • Amazon — Fire TV devices
    Vulnerable versions: Variant abusing Fire TV Home Screen launcher

Remediation for Android.MagicAd Trojan Floods Devices with Ads via Xiaomi

Immediate actions

  • Uninstall apps flagged as Android.MagicAd.1 / Android.MagicAd.1.origin and any recently installed games or modified 'pro/plus' app builds that hide their icon or show out-of-context full-screen ads
  • Block and remove sideloaded APKs sourced from third-party sites such as Apkmody and Moddroid via MDM policy
  • On managed Android/Vivo/Fire TV fleets, audit for apps spawning persistent background services with hidden launcher icons

Workarounds

  • Disable sideloading / unknown-sources installation
  • Review and revoke ability of non-system apps to launch foreground services and schedule background tasks where MDM allows
  • Remove preinstalled bloat/system apps that are abused as ad-surface targets where the platform permits

Longer-term hardening

  • Deploy a reputable mobile EDR/AV with behavioral detection for runtime dex loading, translucent-activity ad rendering, and icon hiding
  • Restrict installs to vetted enterprise app catalogs and disable installation from unknown sources via MDM
  • Enable Google Play Protect and keep it on; monitor for re-uploaded clones of removed titles
  • Educate users not to install 'modded' versions of Spotify, YouTube, Deezer, Netflix and similar apps

Weaknesses (CWE) in Android.MagicAd Trojan Floods Devices with Ads via Xiaomi

CWE-919, CWE-507, CWE-829

Timeline of Android.MagicAd Trojan Floods Devices with Ads via Xiaomi

  • Android.MagicAd first appears in the wild, distributed through legitimate and third-party Android app sources (Doctor Web, year-of-first-observation per Q1 2026 review).
  • Android.MagicAd embedded in more than 50 games and programs on Xiaomi's official GetApps catalog, with infected titles rotated roughly monthly to evade takedown.
  • Variants identified on the Samsung Galaxy Store and distributed via third-party APK sites Apkmody and Moddroid as modified versions of popular apps.
  • Device-specific variants observed targeting Vivo smartphones (abusing iManager, Phonebook, Vivo Browser, Baidu IME via Binder) and Amazon Fire TV devices (abusing the Fire TV Home Screen launcher).
  • Public reporting (The420 and others) highlights Dr.Web findings on Android ad-fraud trojans abusing Xiaomi GetApps.
  • Doctor Web documents Android.MagicAd in its Q1 2026 mobile virus-activity review, detailing translucent-activity ad rendering, encrypted native-library dex loading, and watchdog persistence.
  • Doctor Web releases Android.MagicAd indicators of compromise via its public malware-iocs GitHub repository (github.com/DoctorWebLtd/malware-iocs) for defender consumption.
  • Doctor Web publishes its dedicated Android.MagicAd advisory (news.drweb.com/show/?i=15262) describing per-device ad-display techniques, SYSTEM_ALERT_WINDOW bypass, system media-player abuse, and the abuse of built-in apps (Mi Browser, MIUI SystemUI, Fire TV launcher, Vivo iManager/Phonebook/Browser/Baidu IME).
  • Wider security press (Cyber Security News, GBHackers) publish detailed analyses of Android.MagicAd; threat tracked as ACTIVE.

Sources cited for Android.MagicAd Trojan Floods Devices with Ads via Xiaomi

Detection coverage for TL-2026-0737

As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0737 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats