Vulnerabilità · 132 giorni fa
Questo è stato costruito per abusare del carrier billing end to end, non solo per distribuire app false. Il malware controllava l’operatore SIM, forzava il traffico cellulare e inviava automaticamente gli OTP, così gli abbonamenti premium potevano essere attivati sulla bolletta mobile della vittima senza la normale frizione per l’utente.
2 fonti che coprono questa storia
Fake Android Apps Commit Carrier Billing Fraud for Premium Services
The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions.
Android Malware Used Fake Apps to Charge Users in Mass Billing Scam
Premium Deception campaign uses 250 Android apps to silently sign victims up to paid services
Part of the PlainSec briefing for 2026-05-21