Aftercall ads are driving Android users crazy
2026-07-27T20:51:45Z•e030015c55f7511ce3986f2d9ebfef2e351087556a170b12c3a72df98e7bd2a5
2fa-theftaccount-takeoverad-fraudamatera-stealerandroidautomotive-securitybrowser-extensioncredential-theftdata-breachetherhidinghermeticreaderimpersonationinfostealermacosmalwaremsbuildphishingprivacyrenpy-loaderscamssextortionwordpresswp2shell
What happened
Malwarebytes Labs’ July 20–27, 2026 feed covers Android ad fraud, phishing and account theft, sextortion and impersonation scams, data breaches, software and automotive vulnerabilities, macOS infostealers, WordPress exploitation, piracy-based malware distribution, and loader campaigns delivering Amatera Stealer. Reported activity includes full-screen Android ads triggered after calls, credential and 2FA theft via fake Call of Duty Points sites, ClickLock Stealer persistence on macOS, Ren’Py/MSBuild/EtherHiding delivery chains, and exploitation of wp2shell and HermeticReader vulnerabilities. It
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- e030015c55f7511ce3986f2d9ebfef2e351087556a170b12c3a72df98e7bd2a5
- Enrichment time
- 2026-07-27T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.