Urgent.News

What's breaking now, across thousands of outlets.

Tech

Meta ads steered Polish Android users into a premium-rate billing trap

CERT Polska linked 852 promotions to 17 Google Play apps capable of sending costly texts or starting recurring subscriptions

Meta ads steered Polish Android users into a premium-rate billing trap

Poland's Computer Emergency Response Team (CERT Polska) has uncovered a toll fraud campaign that employed paid Meta ads to direct Polish users towards malicious apps on Google Play. The investigation revealed 1,235 Meta ads, with 852 promoting 17 apps connected to the operation. Six of these ads contained confirmed toll fraud components or direct links to them, while the remaining 11 shared malicious loaders.

Toll fraud involves malware enrolling mobile subscribers in paid services without their consent, often through premium-rate SMS or automated carrier billing. CERT identified two billing routes, with charges ranging from 17 PLN ($4.41) per week to 30.75 PLN ($7.97) per message. Three specific short codes and a separate carrier billing offer operated by Teleaudio were linked to the campaign.

The investigation started with two fraudulent Facebook ads warning users about expired PDF applications, which led to the Google Play listing for Messenger Pro, an SMS app containing the malicious loader. CERT subsequently discovered nine TikTok ads promoting another app from the campaign, although the hidden code followed a different path.

The operation leveraged both Meta and Google Play, with Meta providing paid acquisition to Polish users and Google Play serving as the installation path. Messenger Pro functioned as an SMS app and could request to become the device's default message handler, while its base APK reconstructed an encrypted DEX file at runtime. The loader checked the package name and mobile country code, contacted a policy server, decrypted another DEX, and downloaded the final fraud payload from Alibaba Cloud Object Storage Service.

CERT reported the malicious app to Google on September 15 and reported all uncovered apps to Google. Google removed the identified apps from Play, while Meta took down the ads reported. The command-and-control infrastructure remained active, issuing jobs to controlled Polish registrations, and new packages appeared after Google removed the reported apps.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Thursday 24 September →