Android Malware Secretly Signs Users Up for Premium Services
ID: 596c161a-49a0-5297-9547-d9bc00b689c7
STIX ID: report--596c161a-49a0-5297-9547-d9bc00b689c7
Feed Name: GBHackers
A widespread Android malware campaign (≈250 malicious apps) has been exploiting carrier billing systems since March 2025 by impersonating popular apps and selectively targeting users based on their mobile operator to auto-subscribe victims to premium SMS services. The operation uses WebView/JavaScript automation, Google SMS Retriever API abuse for OTP interception, forced cellular usage, cookie theft, and Telegram-based exfiltration; researchers observed three variants and identified related domains and premium short codes across Malaysia, Thailand, Romania, and Croatia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
