Vulnerabilities · 117 days ago
This was built to abuse carrier billing end to end, not just to push fake apps. The malware checked the SIM operator, forced cellular traffic, and auto-submitted OTPs so premium subscriptions could be opened on the victim’s mobile bill without normal user friction.
Zimperium’s zLabs says the Premium Deception campaign ran for about 10 months, from March 2025 to mid-January 2026, and used nearly 250 impersonation apps. The apps copied brands like Facebook Messenger, Instagram Threads, TikTok, Minecraft, and Grand Theft Auto, and the hardcoded targeting focused on Malaysia, Thailand, Romania, and Croatia.
Portions of the infrastructure are still online. That makes this an active fraud system, and it means handset cleanup alone does not erase the carrier-billed subscriptions or the billing abuse already in motion.
2 sources covering this story
Fake Android Apps Commit Carrier Billing Fraud for Premium Services
The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions.
Android Malware Used Fake Apps to Charge Users in Mass Billing Scam
Premium Deception campaign uses 250 Android apps to silently sign victims up to paid services
Part of the PlainSec briefing for 2026-05-21