Hackers Exploit Multiple Ad Networks to Distribute Triada Malware to Android Users
## Neutralization of Triada Trojan Malware Operation
Neutralization of Triada Trojan Malware Operation
Adex, part of AdTech Holding, has effectively dismantled a complex malware operation connected to the Triada Trojan, which targeted the mobile advertising ecosystem. This operation highlights the risks associated with supply-chain attacks in digital advertising.
According to industry data, Triada accounted for 15.78% of all Android malware detections in Q3 2025. Adex analysts found that threat actors responsible for Triada have been infiltrating legitimate advertising networks over the past five years.
Attackers have shifted from traditional infection methods to exploiting high-trust infrastructures. They compromised advertiser accounts and used platforms like GitHub and Discord CDNs to distribute malicious APK files through cloaked redirects, making detection challenging for standard security measures.
Adex documented three phases of activity demonstrating modern fraud tactics. From 2020 to 2021, attackers bypassed Know Your Customer (KYC) protocols with low-quality forged documents. Malware was distributed via Discord CDNs and URL shorteners.
This operation highlights the risks associated with supply-chain attacks in digital advertising.
Between 2022 and 2024, tactics evolved to account takeovers, targeting accounts without two-factor authentication. Compromised profiles launched campaigns redirecting users to payloads on GitHub, leveraging the trust of established code repositories.
In 2025, the operation reached high complexity, using phishing pre-landers imitating Chrome updates and multi-step redirects to obscure malicious destinations. VirusTotal data linked this activity to suspicious logins from Turkey and India. Adex has banned over 500 accounts related to this operation.
The evolution of Triada demonstrates how ad networks can inadvertently facilitate malware distribution. Adex has responded by implementing a comprehensive business-protection strategy. This includes stricter KYC procedures, mandatory two-factor authentication, and login anomaly monitoring for all advertiser accounts.
The strategy also mandates full redirect and domain verification, even for campaigns involving trusted services. These measures have fortified the ecosystem against future threats.
Based on reporting by GBHackers.
