{"id":207273,"date":"2026-01-28T05:47:00","date_gmt":"2026-01-28T10:47:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/01\/28\/phantom-malware-in-android-game-mods-hijacks-devices-for-ad-fraud-hackread-cybersecurity-news-data-breaches-ai-and-more\/"},"modified":"2026-01-28T05:55:09","modified_gmt":"2026-01-28T10:55:09","slug":"phantom-malware-in-android-game-mods-hijacks-devices-for-ad-fraud-hackread-cybersecurity-news-data-breaches-ai-and-more","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/01\/28\/phantom-malware-in-android-game-mods-hijacks-devices-for-ad-fraud-hackread-cybersecurity-news-data-breaches-ai-and-more\/","title":{"rendered":"Phantom Malware in Android Game Mods Hijacks Devices for Ad Fraud \u2013 Hackread \u2013 Cybersecurity News, Data Breaches, AI, and More"},"content":{"rendered":"<p><a href=\"https:\/\/hackread.com\/phantom-malware-android-game-mods-ad-fraud\/\">Phantom Malware in Android Game Mods Hijacks Devices for Ad Fraud \u2013 Hackread \u2013 Cybersecurity News, Data Breaches, AI, and More<\/a><\/p>\n<p><a href=\"https:\/\/hackread.com\/phantom-malware-android-game-mods-ad-fraud\/\">https:\/\/hackread.com\/phantom-malware-android-game-mods-ad-fraud\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-01-28 05:47:00<\/a><\/p>\n<p>Source Domain: <a href=\"hackread.com\">hackread.com<\/a><\/p>\n<p class=\"is-style-cnvs-paragraph-callout\">Phantom malware hidden in Android game mods hijacks devices to run covert ad fraud, using remote control and machine learning to mimic user behavior.<\/p>\n<p class=\"has-drop-cap\">Android Smartphone owners installing modified games and apps are now facing yet another threat that turns their devices into tools for click fraud, researchers at Doctor Web\u2019s antivirus lab report. The malware, part of a family tracked as Android.Phantom, has been found bundled with popular titles and spreads through unofficial app sources and third\u2011party stores.<\/p>\n<p>Researchers first noticed this strain after several Android games began behaving suspiciously following updates in late September 2025 from a single developer account. Titles such as Creation Magic World, Cute Pet House, and Theft Auto Mafia were clean before September 2025, but later distributed versions bundled with the trojan. Once installed, the malware launches along with the game without any visible alert to the user.<\/p>\n<p>Two of the malicious apps flagged by researchers, among several identified in the campaign (Image credit: Doctor Web)<\/p>\n<p>According to Doctor Web\u2019s report, the Android.Phantom family operates in two modes controlled by commands from remote servers. In the so\u2011called \u201cphantom\u201d mode, the malware uses a hidden browser component to load specified web pages, then downloads a script and a machine\u2011learning model to analyse and interact with ads, mimicking real user clicks. It also pulls Machine\u2011learning code from an external host to assist in automating this interaction.<\/p>\n<p>In its alternate mode, the malware sets up peer\u2011to\u2011peer connections using WebRTC, allowing remote controllers to see and interact with the user\u2019s virtual screen in real time. That remote session can perform actions such as scrolling, tapping, and text input directly on the infected device.<\/p>\n<p>Doctor Web also noted that the use of Android.Phantom toolkit has grown over time, with regular updates adding new capabilities. An additional module&#8230;<\/p>\n<p><a href=\"https:\/\/hackread.com\/phantom-malware-android-game-mods-ad-fraud\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Phantom Malware in Android Game Mods Hijacks Devices for Ad Fraud \u2013 Hackread \u2013 Cybersecurity&#8230;<\/p>\n","protected":false},"author":1,"featured_media":207274,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/hackread.com\/wp-content\/uploads\/2026\/01\/phantom-malware-android-game-mods-ad-click-fraud-1024x597.jpg","fifu_image_alt":"","footnotes":""},"categories":[46],"tags":[32],"class_list":["post-207273","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","tag-malware"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207273"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=207273"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207273\/revisions"}],"predecessor-version":[{"id":207275,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/207273\/revisions\/207275"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/207274"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=207273"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=207273"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=207273"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}