<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Ad Fraud</title><description>Cybersecurity articles tagged #Ad Fraud on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>ClickFix Campaign Exploits Polygon Blockchain for C2 Evasion</title><link>https://runtimerebel.com/blog/clickfix-campaign-exploits-polygon-blockchain-for-c2-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-campaign-exploits-polygon-blockchain-for-c2-evasion</guid><description>The ClickFix campaign compromises 31 organizations, dynamically updating its C2 server via EtherHiding and the Polygon blockchain.</description><pubDate>Tue, 01 Sep 2026 19:01:53 GMT</pubDate><category>ClickFix</category><category>C2 Evasion</category><category>Ad Fraud</category><category>EtherHiding</category><category>Polygon Blockchain</category></item><item><title>Android Car Head Units Infected by MoYu Proxy Botnet Malware</title><link>https://runtimerebel.com/blog/android-car-head-units-infected-by-moyu-proxy-botnet-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-car-head-units-infected-by-moyu-proxy-botnet-malware</guid><description>A supply-chain attack by MoYu Group uses a legitimate update app to infect Android car head units, forming a proxy botnet for ad fraud.</description><pubDate>Sat, 22 Aug 2026 16:13:49 GMT</pubDate><category>Android Malware</category><category>Proxy Botnet</category><category>Supply Chain Attack</category><category>Ad Fraud</category><category>MoYu Group</category></item><item><title>Android Car Head Unit Malware Spreads via Built-In Updaters</title><link>https://runtimerebel.com/blog/android-car-head-unit-malware-spreads-via-built-in-updaters</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-car-head-unit-malware-spreads-via-built-in-updaters</guid><description>Kaspersky discovered a new malware family targeting Android car head units via DoFun firmware updaters to build an ad fraud and proxy botnet.</description><pubDate>Sat, 22 Aug 2026 16:13:11 GMT</pubDate><category>Malware</category><category>Android</category><category>Ad Fraud</category><category>Botnet</category></item><item><title>Fuyao Operation: Android TV Boxes Mimic Phones, Hijack Bandwidth</title><link>https://runtimerebel.com/blog/fuyao-operation-android-tv-boxes-mimic-phones-hijack-bandwidth</link><guid isPermaLink="true">https://runtimerebel.com/blog/fuyao-operation-android-tv-boxes-mimic-phones-hijack-bandwidth</guid><description>Cheap Android TV boxes are pre-installed with Fuyao malware, impersonating phones for ad fraud and turning devices into residential proxy nodes.</description><pubDate>Fri, 31 Jul 2026 17:41:21 GMT</pubDate><category>Fuyao</category><category>Android TV Box</category><category>Ad Fraud</category><category>Proxy Network</category><category>Zhejiang Fengwo IoT Technology Co Ltd</category><category>Supply Chain Compromise</category><category>Mobile Impersonation</category></item><item><title>Generic Streaming Sticks: Covert Proxy Networks &amp; Ad Fraud Exposed</title><link>https://runtimerebel.com/blog/generic-streaming-sticks-covert-proxy-networks-ad-fraud-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/generic-streaming-sticks-covert-proxy-networks-ad-fraud-exposed</guid><description>Generic TV streaming sticks are being used in a dual-pronged attack: creating a covert proxy network and engaging in extensive ad fraud through spoofed mobile traffic on…</description><pubDate>Thu, 30 Jul 2026 17:31:49 GMT</pubDate><category>Ad Fraud</category><category>Proxy Network</category><category>Streaming Devices</category><category>Iot Security</category><category>Botnet</category><category>Consumer Devices</category></item><item><title>Popa Botnet Linked to Alarum Technologies’ NetNut Proxy Service</title><link>https://runtimerebel.com/blog/popa-botnet-linked-to-alarum-technologies-netnut-proxy-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/popa-botnet-linked-to-alarum-technologies-netnut-proxy-service</guid><description>Researchers link the massive Popa Android botnet to NetNut, a residential proxy provider. The botnet exploits millions of TV boxes for fraud and scraping.</description><pubDate>Fri, 19 Jun 2026 09:47:40 GMT</pubDate><category>Popa Botnet</category><category>NetNut</category><category>Alarum Technologies</category><category>Android Malware</category><category>Residential Proxy</category><category>Ad Fraud</category></item><item><title>Trapdoor Android Ad Fraud: 455 Apps Generate 659M Daily Bid Requests</title><link>https://runtimerebel.com/blog/trapdoor-android-ad-fraud-455-apps-generate-659m-daily-bid-requests</link><guid isPermaLink="true">https://runtimerebel.com/blog/trapdoor-android-ad-fraud-455-apps-generate-659m-daily-bid-requests</guid><description>Researchers reveal the Trapdoor ad fraud scheme, involving 455 Android apps and 183 C2 domains generating over 600 million daily fraudulent bid requests.</description><pubDate>Tue, 19 May 2026 20:39:59 GMT</pubDate><category>Android</category><category>Ad Fraud</category><category>Trapdoor</category><category>HUMAN Satori</category><category>Malvertising</category></item><item><title>Android 17 Privacy Overhaul: Google Blocks 8.3B Malicious Ads</title><link>https://runtimerebel.com/blog/android-17-privacy-overhaul-google-blocks-8-3b-malicious-ads</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-17-privacy-overhaul-google-blocks-8-3b-malicious-ads</guid><description>Google announces Android 17 privacy updates and Play policy changes after blocking 8.3 billion ads and 24.9 million fraudulent accounts throughout 2025.</description><pubDate>Fri, 17 Apr 2026 12:27:55 GMT</pubDate><category>Google Ad Safety</category><category>Android 17</category><category>Privacy Updates</category><category>Ad Fraud</category><category>Play Policy Updates</category></item><item><title>Pushpaganda Scam: Detecting AI-Driven Ad Fraud in Google Discover</title><link>https://runtimerebel.com/blog/pushpaganda-scam-detecting-ai-driven-ad-fraud-in-google-discover</link><guid isPermaLink="true">https://runtimerebel.com/blog/pushpaganda-scam-detecting-ai-driven-ad-fraud-in-google-discover</guid><description>Researchers unmask Pushpaganda, a campaign using AI-generated content and SEO poisoning to trick users into enabling malicious browser notifications.</description><pubDate>Tue, 14 Apr 2026 16:31:22 GMT</pubDate><category>Pushpaganda</category><category>Google Discover</category><category>Ad Fraud</category><category>Scareware</category><category>Ai Generated Content</category></item></channel></rss>