Mobile security is going through another period of intense testing, as advanced malware constantly upgrades its techniques to bypass modern defenses. One of the most striking examples of this trend is the reemergence of the Triada Trojan, a sneaky Android malware that has been around for almost a decade and is now back with a highly coordinated operational campaign.

This new activity, recently uncovered by the Adex, demonstrates how capable Triada has become in penetrating extensive advertising networks, leveraging infrastructures that were previously considered secure.
A Trojan that evolves methodically
Triada no longer relies on simple deception techniques; instead, it exploits legitimate web traffic to distribute its malicious payloads. This makes its activity more difficult to detect, and its presence has already compromised a large number of Android devices.
See also: Cybersecurity: Preparing Retailers for the Holiday Season
Attackers are showing impressive adaptability: from forged documents and simple fraud techniques, they have now moved on to much more sophisticated hijackings of advertiser accounts. These accounts—often without 2FA enabled—are used to launch suspicious campaigns that appear perfectly legitimate.
Malicious display through… trusted platforms
One of the most worrying elements of the new campaign is the use of platforms that users trust, such as GitHub and Discord. The attacks redirect unsuspecting victims to malicious content hosted there, making detection by automated systems even more difficult.
According to Adex, Triada's activity now accounts for over 15% of all Android malware infections in the third quarter of 2025. This is an impressively high proportion that demonstrates the Trojan's longevity, persistence, and constant adaptation.
Waves of attacks with increasing technical complexity
During the research, analysts observed that the attacks are occurring in “waves,” each more sophisticated than the previous one. The early stages (2020–2021) focused on bypassing Know Your Customer (KYC) through fake identities and repeated requests.
These methods were supported by URL shorteners and CDN networks that “hid” the true identity of landing pages. But in 2022, the tactics changed: ad accounts without adequate security mechanisms were now targeted.
See also: Crypto user loses $9,000 in seconds after clicking on Instagram ad

The latest wave of 2025 introduced a particularly disturbing innovation: phishing pages, designed to look like legitimate Chrome update notifications. These pages use multiple, cascading redirects to hide the true source of the malicious file.
Global footprint and coordinated execution
Analysis of the logs showed suspicious login attempts to accounts from Turkey and India. Experts believe these are systematic attempts to collect credentials, with the aim of creating a powerful network of compromised accounts that can be used to mass distribute the Triada Trojan.
The increasingly sophisticated infrastructure of the attacks indicates that this is an organized group with significant resources and a high level of technical training.
The consequences for digital advertising
With Triada exploiting vulnerabilities in ad networks’ systems, the credibility of the ecosystem is at risk. The attacks not only infect devices, but also undermine the advertising economy, generating revenue from fake clicks, deceptive campaigns, and illegal app installations.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Businesses that rely on digital advertising risk seeing their accounts compromised, while users are exposed to even more sophisticated forms of phishing.
See also: Exploiting vulnerabilities in Sneeit WordPress and ICTBroadcast fuels Frost botnet

Need for zero-trust models
The new wave of attacks demonstrates that traditional protection measures are not enough. Experts emphasize the need for:
- Mandatory multi-factor authentication (MFA)
- Strict domain verification
- Real-time recording and monitoring of suspicious behaviors
- “Zero trust” strategies for all levels of networks
Triada's comeback with such sophisticated tactics is a clear warning: attacks in the Android space show no signs of slowing down — and the digital ecosystem must adapt immediately.
