# Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled Vivo / Amazon Fire TV Apps

> Android.MagicAd is an in-the-wild Android adware trojan that floods infected devices with persistent background advertisements while bypassing Android's overlay-permission and analysis-resistance controls. Doctor Web found it embedded in 50+ games and apps on Xiaomi's GetApps store and the Samsung Galaxy Store, in third-party APK mods on Apkmody/Moddroid, and as variants targeting Vivo smartphones and Amazon Fire TV devices, with infected titles rotated roughly monthly to evade detection.

- **Published:** 2026-06-09T00:00:00Z
- **Last reviewed:** 2026-06-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0737
- **ID:** TL-2026-0737
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Android.MagicAd (Doctor Web detections Android.MagicAd.1 and its dex component Android.MagicAd.1.origin) is a mobile adware/ad-fraud trojan first observed in the wild in 2025 and detailed in Doctor Web's Q1 2026 mobile virus-activity review. Its primary objective is monetization through aggressive, unsolicited advertising rather than data theft, but its evasion and persistence engineering make it notable as a widely distributed mobile threat warranting dedicated detection coverage.

Distribution is multi-channel and abuses trusted supply chains. Doctor Web found MagicAd concealed in more than 50 games and programs on Xiaomi's official GetApps catalog, with additional variants on the Samsung Galaxy Store. The operators rotated their uploads: an infected app typically remained available for roughly one month before being pulled and replaced with a freshly uploaded title, a tactic that both extends campaign lifetime and frustrates signature-based takedowns. The trojans were also pushed through third-party APK sites such as Apkmody and Moddroid, frequently masquerading as modified ('mod') builds of popular services. Beyond app-store delivery, MagicAd appeared as device-specific variants on Vivo smartphones and Amazon Fire TV devices, indicating compromise or abuse of preinstalled/system-app channels on those platforms.

Part of MagicAd's malicious functionality is hidden inside encrypted native libraries stored in the app's resource directory. At runtime the trojan decrypts these libraries, extracts dex components from them, and executes the embedded modules — keeping the malicious logic out of static view of store-vetting and many scanners. Before displaying any ads, MagicAd performs environment-safety checks: it searches for virtual-machine / emulator artifacts, verifies whether the installation appears 'organic' (a real user install rather than an automated/analysis install), and filters the device's IP address against a blacklist, suppressing activity in suspected analysis environments.

MagicAd's defining trait is displaying advertisements without requesting the SYSTEM_ALERT_WINDOW permission that normally gates screen overlays. Instead it renders ad banners as Translucent Activity windows, which surface on screen without triggering the usual overlay-permission checks. To reach and wake system surfaces, it sends crafted Intents (including pending intents) to built-in apps that process intents even when not explicitly launched: on Xiaomi devices it targets Mi Browser and the MIUI SystemUI shell; on Amazon devices it leverages the Fire TV Home Screen launcher; on Vivo devices it uses the lower-level Android Binder channel against iManager, Phonebook, Vivo Browser, and a customized Baidu IME. A platform-agnostic fallback decrypts an audio file embedded in the trojan's body, writes it to its working directory, launches the system media player at zero volume, and simulates button presses to silently trigger ad playback/interaction.

For persistence the trojan hides its launcher icon from the app menu, spawns multiple silent background/foreground services backed by notification channels, and registers task-scheduler 'watchdog' jobs that periodically restart its services. On older Android versions it can launch a virtual screen to keep itself alive and prevent the system from shutting it down. Multiple fallback methods with retry logic ensure the ad-delivery and persistence loops continue even after the originating app is removed from a store. Defenders should treat MagicAd primarily as an ad-fraud / resource-abuse and trust-erosion threat on Android, Vivo, and Fire TV estates and prioritize behavioral detection (icon hiding, translucent-activity ad rendering, runtime dex loading from encrypted native libs, watchdog re-spawn, and intent abuse against system apps).

## MITRE ATT&CK

- T1660 Phishing
- T1474.003 Compromise Software Supply Chain
- T1474.002 Compromise Hardware Supply Chain
- T1407 Download New Code at Runtime
- T1575 Native API
- T1603 Scheduled Task/Job
- T1624.001 Broadcast Receivers
- T1541 Foreground Persistence
- T1628.001 Suppress Application Icon
- T1628.002 User Evasion
- T1406.002 Software Packing
- T1406.001 Steganography
- T1633.001 System Checks
- T1655.001 Match Legitimate Name or Location
- T1418 Software Discovery
- T1426 System Information Discovery
- T1422 System Network Configuration Discovery
- T1437.001 Web Protocols
- T1516 Input Injection
- T1643 Generate Traffic from Victim

## Sources

- [New MagicAd Android Malware Floods Devices with Ads](https://cybersecuritynews.com/new-magicad-android-malware-flood-device/)
- [Android.MagicAd trojan displays ads despite all restrictions](https://news.drweb.com/show/?i=15262&lng=en&c=5)
- [MagicAd Android Malware Bypasses Restrictions to Flood Devices With Ads](https://gbhackers.com/magicad-android-malware/)
- [Doctor Web's Q1 2026 review of virus activity on mobile devices](https://news.drweb.com/show/review/?lng=en&i=15136)
- [Android.MagicAd.1 — Dr.Web Malware description library](https://vms.drweb.com/virus/?_is=1&i=Android.MagicAd.1)
- [Mobile Malware Turns Android Phones Into Silent Engines of Ad Fraud (The420)](https://the420.in/android-click-fraud-malware-dr-web-xiaomi-getapps-machine-learning/)
- [MITRE ATT&CK for Mobile — Hide Artifacts: Suppress Application Icon (T1628.001)](https://attack.mitre.org/techniques/T1628/001/)
- [Doctor Web malware-iocs repository (Android.MagicAd IOCs)](https://github.com/DoctorWebLtd/malware-iocs)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0737
