logo

Android Malware Secretly Signs Users Up for Premium Services

ID: 596c161a-49a0-5297-9547-d9bc00b689c7

STIX ID: report--596c161a-49a0-5297-9547-d9bc00b689c7

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: Mayura Kathir

...
...

A widespread Android malware campaign (≈250 malicious apps) has been exploiting carrier billing systems since March 2025 by impersonating popular apps and selectively targeting users based on their mobile operator to auto-subscribe victims to premium SMS services. The operation uses WebView/JavaScript automation, Google SMS Retriever API abuse for OTP interception, forced cellular usage, cookie theft, and Telegram-based exfiltration; researchers observed three variants and identified related domains and premium short codes across Malaysia, Thailand, Romania, and Croatia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.