logo

Premium Deception: Uncovering a Global Android Carrier Billing Fraud Campaign

ID: 6e9afd2e-1382-5ef8-a6b0-c7bda72b0fc6

STIX ID: report--6e9afd2e-1382-5ef8-a6b0-c7bda72b0fc6

Feed Name: Zimperium Blog

Threat Score
78/100

Date Published: 2026-05-20

Date Updated: 2026-05-21

...
...

zLabs discovered a coordinated Android malware campaign (≈250 malicious apps) performing large-scale carrier billing fraud in Malaysia, Thailand, Romania, and Croatia by targeting specific mobile operators; the malware automates premium subscriptions via hidden WebViews and JavaScript injection, intercepts OTPs using the Google SMS Retriever API, steals session cookies, disables WiFi to force cellular billing, and exfiltrates device and HTML data (including via Telegram), with active C2 infrastructure and identified short codes and domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.