Facebook Ads TradingView Brokewell malvertising campaign targeting Android and Windows users
Campaign
Summary
Hide ▲
Show ▼
A Facebook Ads malvertising campaign is pushing a fake premium TradingView Android app that deploys Brokewell, reaching tens of thousands of users in the European Union and expanding to Windows desktops. The operation uses brand impersonation and malicious ads to move victims into malware installs across mobile and desktop environments.
Related Happenings
Massiv Android trojan device-takeover and credential-theft activity
Malware Activity
H score29
First: 19.02.2026 12:24
Last: 19.02.2026 12:24
Sources 1
About this happening:
The Massiv Android trojan has been disclosed as a device-takeover threat that can steal banking credentials and enable fraudulent transactions. It uses screen streaming*...
Massiv Android trojan device-takeover and credential-theft activity
Malware ActivityAbout this happening: The Massiv Android trojan has been disclosed as a device-takeover threat that can steal banking credentials and enable fraudulent transactions. It uses screen streaming*...
Massiv Android banking malware disguised as IPTV app
Malware Activity
H score27
First: 19.02.2026 12:00
Last: 19.02.2026 12:00
Sources 1
About this happening:
The Massiv Android banking malware is posing as an IPTV app to steal digital identities and access online banking accounts. It uses screen overlays, keylogging...
Massiv Android banking malware disguised as IPTV app
Malware ActivityAbout this happening: The Massiv Android banking malware is posing as an IPTV app to steal digital identities and access online banking accounts. It uses screen overlays, keylogging...
Android click-fraud trojans using TensorFlow.js to automate hidden ad taps
Malware Activity
H score20
First: 22.01.2026 00:07
Last: 22.01.2026 00:07
Sources 1
About this happening:
The Android click-fraud trojan family now uses TensorFlow.js to identify and tap ad elements on Android devices, making fraudulent clicks more adaptive and harder to s...
Android click-fraud trojans using TensorFlow.js to automate hidden ad taps
Malware ActivityAbout this happening: The Android click-fraud trojan family now uses TensorFlow.js to identify and tap ad elements on Android devices, making fraudulent clicks more adaptive and harder to s...
Wonderland Android SMS stealer activity targeting Uzbekistan
Malware Activity
H score27
First: 22.12.2025 08:11
Last: 22.12.2025 08:11
Sources 1
About this happening:
The Wonderland Android SMS stealer is being spread through malicious droppers in attacks targeting users in Uzbekistan, enabling SMS and OTP theft and bank-card fr...
Wonderland Android SMS stealer activity targeting Uzbekistan
Malware ActivityAbout this happening: The Wonderland Android SMS stealer is being spread through malicious droppers in attacks targeting users in Uzbekistan, enabling SMS and OTP theft and bank-card fr...
GoldFactory Southeast Asia mobile fraud campaign using modified banking apps
Campaign
H score32
First: 04.12.2025 11:27
Last: 04.12.2025 11:27
Sources 1
About this happening:
GoldFactory has launched a fresh mobile fraud campaign against users in Indonesia, Thailand, and Vietnam, using government impersonation and modified banking apps...
GoldFactory Southeast Asia mobile fraud campaign using modified banking apps
CampaignAbout this happening: GoldFactory has launched a fresh mobile fraud campaign against users in Indonesia, Thailand, and Vietnam, using government impersonation and modified banking apps...
Timeline
-
01.09.2025 20:28 2 articles · 10mo ago
Fake TradingView ads deliver Brokewell to Android and Windows lures
Campaign Scope UpdateMalicious Facebook ads began promoting a fake premium TradingView Android app to Android users, while the same malvertising operation also used financial and cryptocurrency app lures against Windows desktop users and deployed an improved Brokewell banking trojan. The campaign reached tens of thousands of users in the European Union.
Show sources
- Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans — thehackernews.com — 01.09.2025 20:28
- Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans — thehackernews.com — 01.09.2025 20:28
-
01.09.2025 20:28 1 articles · 10mo ago
Bitdefender warns of Facebook Ads campaign pushing fake TradingView app with Brokewell
Initial DisclosureBitdefender Labs warned that a malvertising operation abusing Facebook Ads was promoting a free premium TradingView Android app that installs an improved Brokewell banking trojan to monitor, control, and steal sensitive information from Android users. The campaign had run at least 75 malicious ads since July 22, 2025 and reached tens of thousands of users in the European Union.
Show sources
- Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans — thehackernews.com — 01.09.2025 20:28