Monday, August 24, 2026

Android Malware Secretly Signs Users Up for Premium Services

Android users are being targeted by a large-scale malware campaign that silently subscribes victims to premium mobile services without their knowledge.

The malware campaign focuses on carrier billing fraud, abusing premium SMS services to generate revenue for attackers. What makes this operation particularly dangerous is its ability to target victims based on their mobile operator selectively.

If a user’s SIM card matches a predefined list of carriers, the malware initiates fraudulent subscription workflows; otherwise, it displays harmless content to avoid detection.

To maximize infections, attackers disguised malicious apps as popular platforms such as Facebook, Instagram, TikTok, Minecraft, and Grand Theft Auto. These fake applications were distributed across multiple channels, tricking users into installing them.

zLabs identified several advanced techniques used by the malware:

  • SIM-based targeting using hardcoded operator lists.
  • WebView manipulation combined with JavaScript injection to automate subscription flows.
  • OTP interception via abuse of Google’s SMS Retriever API.
  • Forced disabling of WiFi to ensure billing transactions occur over cellular networks.
  • Telegram-based exfiltration of device data and fraud activity logs.

If the malware detects a non-targeted operator, it loads benign web content, allowing it to remain undetected on infected devices.

zLabs said in a report shared with GBhackers, the operation involves nearly 250 malicious Android applications and has been actively exploiting users across Malaysia, Thailand, Romania, and Croatia since March 2025.

Researchers uncovered three distinct variants, each with increasing sophistication.

The campaign utilizes a wide array of impersonated app icons ranging from popular games like Minecraft and GTA to social media platforms to lure victims into installation. 

Impersonation apps observed in this campaign (Source : zLabs).
Impersonation apps observed in this campaign (Source : zLabs).

Variant 1 acts as a fully automated subscription engine. It verifies the victim’s carrier and then loads hidden carrier billing pages. Using injected JavaScript, it automatically clicks buttons, requests OTP codes, fills them in, and confirms subscriptions. Victims may see fake prompts, such as game verification messages, masking the fraud.

Variant 2 introduces a multi-stage attack targeting Thai users. It sends premium SMS messages in staggered intervals to avoid detection while simultaneously loading hidden billing pages.

It also steals session cookies using Android applications CookieManager, allowing attackers to maintain authenticated sessions and improve success rates.

Operator and Geographic Targeting Distribution (Source : zLabs).
Operator and Geographic Targeting Distribution (Source : zLabs).

Variant 3 adds real-time monitoring via Telegram. Each infection event, permission grant, or SMS transaction is immediately reported to attacker-controlled channels, including device metadata, operator details, and timestamps.

Android Malware Secretly Signs Users

The campaign relies on a distributed command-and-control infrastructure, including domains such as:

  • apizep.mwmze[.]com.
  • modobomz[.]com.
  • api.modobomco[.]com.

These servers handle subscription automation, victim tracking, and data exfiltration. Attackers also use intermediary redirect URLs to log subscription attempts before redirecting users to legitimate carrier billing portals.

Google’s SMS Retriever API, a legitimate feature designed to help apps automatically read OTP messages for user convenience.


Deceptive screen displaying and loading a hidden webview, requesting permission from the user on the next screen (Source : zLabs).
Deceptive screen displaying and loading a hidden webview, requesting permission from the user on the next screen (Source : zLabs).

Across the campaign, at least 12 premium SMS short codes were identified, targeting multiple operators and countries with specific keywords to trigger paid subscriptions.

A notable feature of this operation is its referrer tracking system. Each infection includes a structured identifier indicating the fake app name, country, platform, and operator.

This allows attackers to measure which distribution channels such as TikTok, Facebook, or Google are most effective, enabling continuous campaign optimization.

Zimperium reports that its Mobile Threat Defense (MTD) and zDefend solutions detect and block all identified samples using on-device behavioral analysis. Unlike signature-based tools, these solutions can identify evolving malware patterns and prevent unauthorized SMS activity and data exfiltration.

Users are advised to avoid downloading apps from unofficial sources, carefully review app permissions, and monitor mobile billing statements for unexpected charges.

Organizations should deploy mobile threat defense solutions to detect and block such advanced fraud campaigns in real time.

Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

New macOS Malware Clones Your Logged-In Browser and Gives Hackers Remote Control.

AmnesiaStealer, a multi-stage macOS infostealer written in Rust that...

Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers

Microsoft is currently investigating a compatibility issue with Windows...

Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access

A critical vulnerability has been identified in the widely...

AWS Network Firewall Adds Rule Hit Counts to Identify Unused Security Rules

AWS has introduced a new capability for AWS Network...

macOS ClickFix Crimekit Uses Polygon Smart Contracts to Deploy AMOS Stealer and XMRig Miner

A macOS-focused ClickFix campaign is abusing Polygon smart contracts...

First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet

A multi-stage Android malware campaign that abuses the firmware-update...

Related Articles

Recent News