logo

Android Carrier Billing Fraud Campaign Exposed by zLabs

ID: e8683fc3-7bf1-50bb-a932-967d0ed78979

STIX ID: report--e8683fc3-7bf1-50bb-a932-967d0ed78979

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Ddos

...
...

zLabs identified a large-scale Android carrier billing fraud campaign distributing roughly 250 fake apps across Malaysia, Thailand, Romania, and Croatia; three variants automate premium subscriptions by abusing SIM and SMS APIs, steal browser cookies to maintain billing access, and exfiltrate device metadata via Telegram, while active infrastructure (for example, modobomz.com) continues to support the operation—users should check billing statements and avoid third-party app sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.