Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users
ID: 1b531af2-5284-5b60-86d0-ad4b62e01f33
STIX ID: report--1b531af2-5284-5b60-86d0-ad4b62e01f33
Feed Name: Infosecurity Magazine (News)
A 10-month Android malware campaign called "Premium Deception" used almost 250 counterfeit apps impersonating popular brands to fraudulently subscribe users to premium SMS services in Malaysia, Thailand, Romania and Croatia. Researchers identified three variants that progressively automated subscription workflows, disabled Wi‑Fi to force carrier billing, harvested OTPs via the SMS Retriever API, exfiltrated session cookies and device status to C2/Telegram, and embedded tracking referrers and abused multiple premium short codes and domains; portions of the infrastructure remained online at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
