Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
How Tier 1 Can Process Alerts 3x Faster with Threat Intel
May 26, 2026
Angular Language Service Flaws Enable Remote Code Execution
May 26, 2026
Quasar Linux RAT Targets Developers via Fileless eBPF
May 26, 2026
Home/Threats/Android Malware Auto-Subscribes Users to Silently Victims
Threats

Android Malware Auto-Subscribes Users to Silently Victims

A newly uncovered Android malware campaign is quietly draining money from mobile users across four countries. This insidious threat operates by silently subscribing victims to premium paid services...

Emy Elsamnoudy
Emy Elsamnoudy
May 22, 2026 4 Min Read
19 0

A newly uncovered Android malware campaign is quietly draining money from mobile users across four countries. This insidious threat operates by silently subscribing victims to premium paid services they never authorized, leading to unexpected charges, as detailed in recent research findings.

The operation ran for nearly ten months and carried out financial fraud entirely behind the scenes, using fake versions of well-known apps as its primary entry point into victims’ devices.

The campaign targeted users in Malaysia, Thailand, Romania, and Croatia, focusing specifically on people subscribed to particular mobile network operators.

Instead of broadly attacking any Android device it landed on, the malware checked a victim’s SIM card first and only acted if the carrier matched a pre-set list. This precision made the fraud far harder to detect and far more effective at avoiding security attention.

Analysts at Zimperium said in a report shared with Cyber Security News (CSN) that their zLabs team discovered nearly 250 malicious applications tied to this campaign.

The malware exploited carrier billing systems, which allow mobile operators to charge users directly through their phone bills rather than requiring a credit card.

The campaign first appeared in March 2025 and remained active through January 2026. Even after parts of the operation were identified, some supporting infrastructure was still live at the time of publication.

Impersonation apps observed in this campaign (Source - Zimperium)
Impersonation apps observed in this campaign (Source – Zimperium)

Fake apps impersonated Facebook Messenger, Instagram Threads, TikTok, Minecraft, and Grand Theft Auto to trick users into installation.

What made this campaign especially dangerous was its use of real platform names and icons to appear completely trustworthy.

Operator and Geographic Targeting Distribution (Source - Zimperium)
Operator and Geographic Targeting Distribution (Source – Zimperium)

Once installed, the app carried out its work while displaying innocent-looking content to keep victims fully unaware. Users had no reason at all to suspect anything was wrong.

Android Malware Silently Subscribes Victims

The zLabs team identified three distinct malware variants, each using a different method to complete unauthorized subscriptions.

The most advanced variant started by reading the victim’s mobile operator from SIM card data, then launched an automated subscription workflow without any visible sign of activity to the user.

This first variant used hidden web pages loaded in the background, all pointing to carrier billing portals. JavaScript commands automatically clicked the subscription button, filled in intercepted OTP codes, and confirmed the transaction.

The malware also disabled the device’s Wi-Fi, forcing all traffic through the cellular network required for carrier billing to succeed. The second variant targeted Thai users and combined silent SMS fraud with browser session hijacking.

It contacted a remote server for updated subscription instructions, allowing attackers to change targets without pushing a new app version. It also stole browser cookies from carrier billing pages to maintain authenticated access to victims’ accounts.

A third variant added real-time reporting through Telegram. Each time the malware installed itself, gained permissions, or sent a premium SMS, it fired an instant message to a private channel controlled by the attackers. Each report included the device ID, carrier name, fake app identity, and the specific action performed.

Malware samples found over the period of time (Source - Zimperium)
Malware samples found over the period of time (Source – Zimperium)

Across all three variants, a referrer tracking system tagged every infection with the fake app name, country, and distribution platform. This gave attackers detailed metrics on which fake apps and social platforms were producing the most successful infections.

Evasion Tactics and Staying Protected

One of the cleverest features of this malware was its behavior on non-targeted devices. Instead of going inactive, the app loaded a harmless webpage to appear completely normal, keeping the malicious apps alive on devices far longer than expected.

To protect against threats like this, users should only download apps from official stores and be cautious of any app requesting SMS reading permissions.

Checking phone bills regularly for unfamiliar charges is a practical way to catch unauthorized subscriptions early. Keeping mobile security software updated adds another important layer of defense against carrier billing fraud.

Indicators of Compromise (IoCs):-

The following infrastructure indicators were identified by Zimperium’s zLabs team as part of this carrier billing fraud campaign.

Type Indicator Description
Domain apizep.mwmze[.]com Hosts DiGi carrier billing subscription pages
Domain modobomz[.]com Central referrer tracking and campaign analytics
Domain api.modobomco[.]com Alternative command and control endpoint
Domain onesignalmdb.modobomz[.]com Victim tracking and referrer validation hub; returns shortcode and keyword for device to send
Domain onesignal.mwmze[.]com Device metadata and carrier billing HTML source exfiltration
Domain apkafa[.]com Benign fallback webpage displayed on non-targeted devices to avoid detection
SMS Short Code +33293 Premium SMS short code used for Malaysia (Maxis) — keyword: ON HITZ
SMS Short Code +32133 Premium SMS short code used for Malaysia (Maxis) — keyword: ON GAM1
SMS Short Code 32128 Premium SMS short code used for Malaysia (U Mobile) — keyword: ON A3
SMS Short Code +1280 (x3) Premium SMS short codes used for Romania (Vodafone, Orange, Telekom)
SMS Short Code 4541545 / +4541341 / +4541753 / +4541370 / +4541587 / +4541162 / +4541352 / +4541544 Additional Romania premium SMS short codes — keywords: MOGA, DA, CYGA, OK, FUVI, BM, GET, CC, VGF, HIH, RTH
SMS Short Code 866866 Premium SMS short code used for Croatia — keyword: GYGO

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Operation Dragon Whistle Targets Changzhou University with Malicious L

Next Post

CISA Warns: Microsoft Defender 0-Day Vulnerabilities Exploited

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Defender Isolates Compromised Devices from Ransom
May 26, 2026
GitHub Down: Authentication Issues Deny Access to Actions
May 26, 2026
Hackers Exploit Ghost CMS CVE-2026 CVE-2026-26980 Poison
May 26, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us