Android Fraud Operation Targets Carrier Billing Systems

This was built to abuse carrier billing end to end, not just to push fake apps. The malware checked the SIM operator, forced cellular traffic, and auto-submitted OTPs so premium subscriptions could be opened on the victim’s mobile bill without normal user friction. Zimperium’s zLabs says the Premium Deception campaign ran for about 10 months, from March 2025 to mid-January 2026, and used nearly 250 impersonation apps. The apps copied brands like Facebook Messenger, Instagram Threads, TikTok, Minecraft, and Grand Theft Auto, and the hardcoded targeting focused on Malaysia, Thailand, Romania, and Croatia. Portions of the infrastructure are still online. That makes this an active fraud system, and it means handset cleanup alone does not erase the carrier-billed subscriptions or the billing abuse already in motion.

Part of the PlainSec briefing for 2026-05-21

Sources