Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Google Play Apps Use Stealth Loaders to Deliver Anatsa Banking Malware
August 10, 2026
Fake Google Translate Chrome Extension Lets Attackers Control Browsers
August 10, 2026
CEVA Logistics Data Breach Exposes Valve Steam Hardware Buyers’ Information
August 10, 2026
Home/Threats/Android Malware Auto-Subscribes Users to Premium Services
Threats

Android Malware Auto-Subscribes Users to Premium Services

Key Takeaways A sophisticated Android malware campaign, active for nearly a year (March 2025 – January 2026), silently subscribed users to unauthorized premium services. The threat specifically...

Emy Elsamnoudy
Emy Elsamnoudy
May 22, 2026 5 Min Read
71 0

Key Takeaways

  • A sophisticated Android malware campaign, active for nearly a year (March 2025 – January 2026), silently subscribed users to unauthorized premium services.
  • The threat specifically targeted mobile users in Malaysia, Thailand, Romania, and Croatia by exploiting carrier billing systems.
  • The malware leveraged fake versions of popular apps like Facebook Messenger, TikTok, and Minecraft to infiltrate devices.
  • Three distinct variants of the malware were identified, employing tactics such as hidden web pages, browser session hijacking, and real-time reporting via Telegram.
  • Users are advised to download apps only from official stores, review app permissions carefully, and regularly check phone bills for suspicious charges.

Android Malware Campaign Silently Drains User Funds via Premium Subscriptions

A recently uncovered Android malware operation has been covertly siphoning money from mobile subscribers across four nations. This sophisticated threat secretly enrolls victims into premium paid services without their consent, leading to unexpected charges on their phone bills, according to detailed research findings.

Table Of Content

  • Key Takeaways
  • Android Malware Campaign Silently Drains User Funds via Premium Subscriptions
  • Deceptive Tactics and Malware Variants
  • Evasion Tactics and Staying Protected
  • What You Should Do

The fraudulent campaign operated for nearly ten months, executing financial deception entirely in the background. Its primary method of infiltration involved distributing counterfeit versions of popular applications to victims’ devices, as outlined in a report published by Zimperium.

The operation specifically targeted mobile network subscribers in Malaysia, Thailand, Romania, and Croatia. Unlike indiscriminate attacks, the malware first verified the victim’s SIM card carrier, activating its malicious functions only if it matched a predefined list. This precise targeting made the fraud considerably more difficult to detect and more effective in evading security measures.

Analysts at Zimperium’s zLabs team reported discovering nearly 250 malicious applications associated with this campaign. The malware exploited carrier billing systems, which enable mobile operators to directly charge users through their phone bills, bypassing the need for credit card transactions.

The campaign commenced in March 2025 and remained active until January 2026. Despite parts of the operation being identified, some of its supporting infrastructure was still operational at the time of the report’s publication.

Deceptive Tactics and Malware Variants

To trick users into installing the malicious apps, attackers impersonated popular platforms and games such as Facebook Messenger, Instagram Threads, TikTok, Minecraft, and Grand Theft Auto. The use of authentic platform names and icons made these fake apps appear entirely legitimate.

Once installed, the applications would display innocuous content, keeping victims completely unaware of the malicious activity occurring in the background. Users had no reason to suspect any wrongdoing while their devices were being compromised.

The zLabs team identified three distinct malware variants, each employing a unique approach to execute unauthorized subscriptions. The most advanced variant initiated its attack by reading the victim’s mobile operator details from the SIM card. It then launched an automated subscription process without any visible indication to the user.

This primary variant utilized hidden web pages that loaded in the background, directing to carrier billing portals. JavaScript commands were then used to automatically click subscription buttons, input intercepted One-Time Passcodes (OTPs), and confirm transactions. Furthermore, the malware disabled the device’s Wi-Fi, forcing all network traffic through the cellular network, a prerequisite for successful carrier billing fraud.

A second variant, specifically targeting Thai users, combined silent SMS fraud with browser session hijacking. This variant communicated with a remote server to receive updated subscription instructions, allowing attackers to modify targets without deploying new app versions. It also stole browser cookies from carrier billing pages to maintain authenticated access to victims’ accounts.

The third variant incorporated real-time reporting capabilities via Telegram. Each instance of malware installation, permission acquisition, or premium SMS dispatch triggered an instant message to a private channel controlled by the attackers. These reports included crucial details such as the device ID, carrier name, the identity of the fake app, and the specific action performed.

Across all three variants, a referrer tracking system was implemented to tag each infection with the fake app name, country, and distribution platform. This provided attackers with precise metrics on the effectiveness of different fake apps and social platforms in generating successful infections.

Evasion Tactics and Staying Protected

A notable feature of this malware was its evasion strategy on non-targeted devices. Instead of remaining dormant, the app would load a harmless webpage. This tactic allowed the malicious applications to persist on devices for extended periods, avoiding early detection.

What You Should Do

  • Download Apps from Official Sources: Only download applications from trusted platforms like the Google Play Store. Avoid third-party app stores or direct downloads from suspicious links.
  • Review App Permissions: Carefully examine the permissions requested by any app, especially those asking for SMS reading, network access, or device administration rights. If an app’s requested permissions seem excessive for its stated functionality, do not install it.
  • Monitor Your Phone Bills: Regularly check your mobile phone bills for any unfamiliar charges or unauthorized premium service subscriptions. Report any suspicious activity to your mobile carrier immediately.
  • Keep Security Software Updated: Ensure your mobile device has up-to-date security software and that its operating system is regularly patched.
  • Be Skeptical of Unsolicited Links: Exercise caution when clicking on links in emails, SMS messages, or social media posts, even if they appear to come from known contacts.

Indicators of Compromise (IoCs):-

The following infrastructure indicators were identified by Zimperium’s zLabs team as part of this carrier billing fraud campaign:

Type Indicator Description
Domain apizep.mwmze[.]com Hosts DiGi carrier billing subscription pages
Domain modobomz[.]com Central referrer tracking and campaign analytics
Domain api.modobomco[.]com Alternative command and control endpoint
Domain onesignalmdb.modobomz[.]com Victim tracking and referrer validation hub; returns shortcode and keyword for device to send
Domain onesignal.mwmze[.]com Device metadata and carrier billing HTML source exfiltration
Domain apkafa[.]com Benign fallback webpage displayed on non-targeted devices to avoid detection
SMS Short Code +33293 Premium SMS short code used for Malaysia (Maxis) — keyword: ON HITZ
SMS Short Code +32133 Premium SMS short code used for Malaysia (Maxis) — keyword: ON GAM1
SMS Short Code 32128 Premium SMS short code used for Malaysia (U Mobile) — keyword: ON A3
SMS Short Code +1280 (x3) Premium SMS short codes used for Romania (Vodafone, Orange, Telekom)
SMS Short Code 4541545 / +4541341 / +4541753 / +4541370 / +4541587 / +4541162 / +4541352 / +4541544 Additional Romania premium SMS short codes — keywords: MOGA, DA, CYGA, OK, FUVI, BM, GET, CC, VGF, HIH, RTH
SMS Short Code 866866 Premium SMS short code used for Croatia — keyword: GYGO

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Operation DragonWhistle Targets Changzhou University with Malicious LNK Files

Next Post

CISA Warns of Actively Exploited Critical Microsoft Defender Vulnerabilities

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Apple Private Cloud Compute Flaw Exposes AI Data, Enables Root Access
August 10, 2026
Critical VS Code Extension Steals Crypto Wallets, API Keys, SSH Keys
August 10, 2026
Kimsuky deploys AsyncRAT via AI lures, local LLMs, and GitHub C2
August 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us