Android Malware Auto-Subscribes Users to Premium Services
Key Takeaways A sophisticated Android malware campaign, active for nearly a year (March 2025 – January 2026), silently subscribed users to unauthorized premium services. The threat specifically...
Key Takeaways
- A sophisticated Android malware campaign, active for nearly a year (March 2025 – January 2026), silently subscribed users to unauthorized premium services.
- The threat specifically targeted mobile users in Malaysia, Thailand, Romania, and Croatia by exploiting carrier billing systems.
- The malware leveraged fake versions of popular apps like Facebook Messenger, TikTok, and Minecraft to infiltrate devices.
- Three distinct variants of the malware were identified, employing tactics such as hidden web pages, browser session hijacking, and real-time reporting via Telegram.
- Users are advised to download apps only from official stores, review app permissions carefully, and regularly check phone bills for suspicious charges.
Android Malware Campaign Silently Drains User Funds via Premium Subscriptions
A recently uncovered Android malware operation has been covertly siphoning money from mobile subscribers across four nations. This sophisticated threat secretly enrolls victims into premium paid services without their consent, leading to unexpected charges on their phone bills, according to detailed research findings.
Table Of Content
The fraudulent campaign operated for nearly ten months, executing financial deception entirely in the background. Its primary method of infiltration involved distributing counterfeit versions of popular applications to victims’ devices, as outlined in a report published by Zimperium.
The operation specifically targeted mobile network subscribers in Malaysia, Thailand, Romania, and Croatia. Unlike indiscriminate attacks, the malware first verified the victim’s SIM card carrier, activating its malicious functions only if it matched a predefined list. This precise targeting made the fraud considerably more difficult to detect and more effective in evading security measures.
Analysts at Zimperium’s zLabs team reported discovering nearly 250 malicious applications associated with this campaign. The malware exploited carrier billing systems, which enable mobile operators to directly charge users through their phone bills, bypassing the need for credit card transactions.
The campaign commenced in March 2025 and remained active until January 2026. Despite parts of the operation being identified, some of its supporting infrastructure was still operational at the time of the report’s publication.
Deceptive Tactics and Malware Variants
To trick users into installing the malicious apps, attackers impersonated popular platforms and games such as Facebook Messenger, Instagram Threads, TikTok, Minecraft, and Grand Theft Auto. The use of authentic platform names and icons made these fake apps appear entirely legitimate.
Once installed, the applications would display innocuous content, keeping victims completely unaware of the malicious activity occurring in the background. Users had no reason to suspect any wrongdoing while their devices were being compromised.
The zLabs team identified three distinct malware variants, each employing a unique approach to execute unauthorized subscriptions. The most advanced variant initiated its attack by reading the victim’s mobile operator details from the SIM card. It then launched an automated subscription process without any visible indication to the user.
This primary variant utilized hidden web pages that loaded in the background, directing to carrier billing portals. JavaScript commands were then used to automatically click subscription buttons, input intercepted One-Time Passcodes (OTPs), and confirm transactions. Furthermore, the malware disabled the device’s Wi-Fi, forcing all network traffic through the cellular network, a prerequisite for successful carrier billing fraud.
A second variant, specifically targeting Thai users, combined silent SMS fraud with browser session hijacking. This variant communicated with a remote server to receive updated subscription instructions, allowing attackers to modify targets without deploying new app versions. It also stole browser cookies from carrier billing pages to maintain authenticated access to victims’ accounts.
The third variant incorporated real-time reporting capabilities via Telegram. Each instance of malware installation, permission acquisition, or premium SMS dispatch triggered an instant message to a private channel controlled by the attackers. These reports included crucial details such as the device ID, carrier name, the identity of the fake app, and the specific action performed.
Across all three variants, a referrer tracking system was implemented to tag each infection with the fake app name, country, and distribution platform. This provided attackers with precise metrics on the effectiveness of different fake apps and social platforms in generating successful infections.
Evasion Tactics and Staying Protected
A notable feature of this malware was its evasion strategy on non-targeted devices. Instead of remaining dormant, the app would load a harmless webpage. This tactic allowed the malicious applications to persist on devices for extended periods, avoiding early detection.
What You Should Do
- Download Apps from Official Sources: Only download applications from trusted platforms like the Google Play Store. Avoid third-party app stores or direct downloads from suspicious links.
- Review App Permissions: Carefully examine the permissions requested by any app, especially those asking for SMS reading, network access, or device administration rights. If an app’s requested permissions seem excessive for its stated functionality, do not install it.
- Monitor Your Phone Bills: Regularly check your mobile phone bills for any unfamiliar charges or unauthorized premium service subscriptions. Report any suspicious activity to your mobile carrier immediately.
- Keep Security Software Updated: Ensure your mobile device has up-to-date security software and that its operating system is regularly patched.
- Be Skeptical of Unsolicited Links: Exercise caution when clicking on links in emails, SMS messages, or social media posts, even if they appear to come from known contacts.
Indicators of Compromise (IoCs):-
The following infrastructure indicators were identified by Zimperium’s zLabs team as part of this carrier billing fraud campaign:
| Type | Indicator | Description |
|---|---|---|
| Domain | apizep.mwmze[.]com | Hosts DiGi carrier billing subscription pages |
| Domain | modobomz[.]com | Central referrer tracking and campaign analytics |
| Domain | api.modobomco[.]com | Alternative command and control endpoint |
| Domain | onesignalmdb.modobomz[.]com | Victim tracking and referrer validation hub; returns shortcode and keyword for device to send |
| Domain | onesignal.mwmze[.]com | Device metadata and carrier billing HTML source exfiltration |
| Domain | apkafa[.]com | Benign fallback webpage displayed on non-targeted devices to avoid detection |
| SMS Short Code | +33293 | Premium SMS short code used for Malaysia (Maxis) — keyword: ON HITZ |
| SMS Short Code | +32133 | Premium SMS short code used for Malaysia (Maxis) — keyword: ON GAM1 |
| SMS Short Code | 32128 | Premium SMS short code used for Malaysia (U Mobile) — keyword: ON A3 |
| SMS Short Code | +1280 (x3) | Premium SMS short codes used for Romania (Vodafone, Orange, Telekom) |
| SMS Short Code | 4541545 / +4541341 / +4541753 / +4541370 / +4541587 / +4541162 / +4541352 / +4541544 | Additional Romania premium SMS short codes — keywords: MOGA, DA, CYGA, OK, FUVI, BM, GET, CC, VGF, HIH, RTH |
| SMS Short Code | 866866 | Premium SMS short code used for Croatia — keyword: GYGO |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.