logo

Android Malware Spotted Subscribing Victims to Paid Services Without Consent

ID: a7772c05-9bf7-5138-b655-01069544fe59

STIX ID: report--a7772c05-9bf7-5138-b655-01069544fe59

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: Deeba Ahmed

...
...

**Executive Summary:** A sustained Android malware campaign (first seen March 2025; active through January 2026) deployed ~250 fake apps impersonating popular brands to perform carrier billing fraud across Thailand, Croatia, Romania, and Malaysia by disabling Wi‑Fi, automating hidden WebView subscription workflows, abusing Google’s SMS Retriever API to capture OTPs/TACs, sending premium SMS to short codes, and exfiltrating data to C2 domains (apizep.mwmze.com, modobomz.com) and Telegram.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.