logo

Android Malware Silently Subscribes Victims to Premium Services Without Consent

ID: 1dfbe5d7-a3bd-5a4a-bc0c-bdf834089fba

STIX ID: report--1dfbe5d7-a3bd-5a4a-bc0c-bdf834089fba

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

An Android malware campaign (Mar 2025–Jan 2026) used ~250 fake apps impersonating popular platforms to silently subscribe victims to premium carrier-billing services in Malaysia, Thailand, Romania, and Croatia; three variants performed SIM-based targeting, background webviews to submit subscriptions and intercept OTPs (including disabling Wi‑Fi), SMS premium fraud and browser session hijacking, and Telegram-based real-time reporting, with multiple domains and premium short codes identified as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.