Android users are being targeted by a large-scale malware campaign that silently subscribes victims to premium mobile services without their knowledge.
The malware campaign focuses on carrier billing fraud, abusing premium SMS services to generate revenue for attackers. What makes this operation particularly dangerous is its ability to target victims based on their mobile operator selectively.
If a user’s SIM card matches a predefined list of carriers, the malware initiates fraudulent subscription workflows; otherwise, it displays harmless content to avoid detection.
To maximize infections, attackers disguised malicious apps as popular platforms such as Facebook, Instagram, TikTok, Minecraft, and Grand Theft Auto. These fake applications were distributed across multiple channels, tricking users into installing them.
zLabs identified several advanced techniques used by the malware:
- SIM-based targeting using hardcoded operator lists.
- WebView manipulation combined with JavaScript injection to automate subscription flows.
- OTP interception via abuse of Google’s SMS Retriever API.
- Forced disabling of WiFi to ensure billing transactions occur over cellular networks.
- Telegram-based exfiltration of device data and fraud activity logs.
If the malware detects a non-targeted operator, it loads benign web content, allowing it to remain undetected on infected devices.
zLabs said in a report shared with GBhackers, the operation involves nearly 250 malicious Android applications and has been actively exploiting users across Malaysia, Thailand, Romania, and Croatia since March 2025.
Researchers uncovered three distinct variants, each with increasing sophistication.
The campaign utilizes a wide array of impersonated app icons ranging from popular games like Minecraft and GTA to social media platforms to lure victims into installation.Â

Variant 1 acts as a fully automated subscription engine. It verifies the victim’s carrier and then loads hidden carrier billing pages. Using injected JavaScript, it automatically clicks buttons, requests OTP codes, fills them in, and confirms subscriptions. Victims may see fake prompts, such as game verification messages, masking the fraud.
Variant 2 introduces a multi-stage attack targeting Thai users. It sends premium SMS messages in staggered intervals to avoid detection while simultaneously loading hidden billing pages.
It also steals session cookies using Android applications CookieManager, allowing attackers to maintain authenticated sessions and improve success rates.

Variant 3 adds real-time monitoring via Telegram. Each infection event, permission grant, or SMS transaction is immediately reported to attacker-controlled channels, including device metadata, operator details, and timestamps.
Android Malware Secretly Signs Users
The campaign relies on a distributed command-and-control infrastructure, including domains such as:
- apizep.mwmze[.]com.
- modobomz[.]com.
- api.modobomco[.]com.
These servers handle subscription automation, victim tracking, and data exfiltration. Attackers also use intermediary redirect URLs to log subscription attempts before redirecting users to legitimate carrier billing portals.
Google’s SMS Retriever API, a legitimate feature designed to help apps automatically read OTP messages for user convenience.

Across the campaign, at least 12 premium SMS short codes were identified, targeting multiple operators and countries with specific keywords to trigger paid subscriptions.
A notable feature of this operation is its referrer tracking system. Each infection includes a structured identifier indicating the fake app name, country, platform, and operator.
This allows attackers to measure which distribution channels such as TikTok, Facebook, or Google are most effective, enabling continuous campaign optimization.
Zimperium reports that its Mobile Threat Defense (MTD) and zDefend solutions detect and block all identified samples using on-device behavioral analysis. Unlike signature-based tools, these solutions can identify evolving malware patterns and prevent unauthorized SMS activity and data exfiltration.
Users are advised to avoid downloading apps from unofficial sources, carefully review app permissions, and monitor mobile billing statements for unexpected charges.
Organizations should deploy mobile threat defense solutions to detect and block such advanced fraud campaigns in real time.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





