The sub-techniques beta is now live! Read the release blog post for more info.


Judy is auto-clicking adware that was distributed through multiple apps in the Google Play Store. [1]

ID: S0325
Platforms: Android
Version: 1.1
Created: 17 October 2018
Last Modified: 11 December 2018

Techniques Used

Domain ID Name Use
Mobile T1407 Download New Code at Runtime

Judy bypasses Google Play's protections by downloading a malicious payload at runtime after installation.[1]

Mobile T1472 Generate Fraudulent Advertising Revenue

Judy uses infected devices to generate fraudulent clicks on advertisements to generate revenue.[1]