Skip to main content
Mallory
Back to intelligence
identity-impersonation-fraudcredential-stealer-activitycommand-and-control-methoddata-exfiltration-method

Android Malware Used 250 Fake Apps for Silent Carrier-Billing Fraud

Updated 11d agoFirst seen May 20, 20264 sources

Researchers at Zimperium’s zLabs uncovered a large Android malware campaign that used nearly 250 malicious apps to silently subscribe victims to premium carrier-billing services and abuse premium SMS flows without consent. The apps impersonated well-known brands and games including Facebook Messenger, Instagram Threads, TikTok, Minecraft, and Grand Theft Auto, and targeted users in Malaysia, Thailand, Romania, and Croatia. The operation was active from March 2025 through January 2026, with some attacker infrastructure still online at the time of reporting.

zLabs identified three malware variants that activated only when a device’s SIM matched specific mobile operators, helping the fraud remain hidden from non-targeted users by showing benign fallback pages. The malware used hidden WebViews and JavaScript to automate subscription pages, intercepted one-time passwords through Google’s SMS Retriever API, disabled Wi‑Fi to force cellular billing, stole cookies, sent delayed premium SMS messages, and reported activity through attacker-controlled Telegram channels. Researchers said the infrastructure supported command-and-control, victim tracking, analytics, and exfiltration of device metadata and billing-page content.

Share:
Android Malware Used 250 Fake Apps for Silent Carrier-Billing Fraud
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 20, 202617d ago

Zimperium publicly discloses campaign and notes active infrastructure

On publication of its research, Zimperium disclosed the global Android fraud campaign and said parts of the attacker infrastructure were still operational. The company described the distributed infrastructure supporting command and control, victim tracking, analytics, and exfiltration of device and billing-page data.

Jan 10, 20265mo ago

Campaign remains active into second week of January 2026

Researchers reported that the malware campaign was still active through the second week of January 2026. They identified three malware variants, including one tailored to Thai users and another that sent operational updates to attacker-controlled Telegram channels.

Mar 1, 20251y ago

Campaign runs across four countries using targeted subscription fraud

From March 2025 through the second week of January 2026, the operation used nearly 250 malicious Android apps to target users in Malaysia, Thailand, Romania, and Croatia. The malware selectively activated based on the victim's SIM operator and used hidden WebViews, OTP interception, Wi‑Fi disabling, cookie theft, premium SMS abuse, and Telegram-based reporting to complete fraudulent subscriptions.

zLabs first detects Android carrier-billing fraud campaign

Zimperium's zLabs first observed a large Android malware operation in March 2025. The campaign used malicious apps posing as popular brands to target users for unauthorized carrier-billing and premium SMS charges.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.