Android Carrier Billing Fraud Campaign Exposed by zLabs
ID: e8683fc3-7bf1-50bb-a932-967d0ed78979
STIX ID: report--e8683fc3-7bf1-50bb-a932-967d0ed78979
Feed Name: securityonline.info
zLabs identified a large-scale Android carrier billing fraud campaign distributing roughly 250 fake apps across Malaysia, Thailand, Romania, and Croatia; three variants automate premium subscriptions by abusing SIM and SMS APIs, steal browser cookies to maintain billing access, and exfiltrate device metadata via Telegram, while active infrastructure (for example, modobomz.com) continues to support the operation—users should check billing statements and avoid third-party app sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
