{
  "id": 9544261,
  "title": "Meta ads steered Polish Android users into a premium-rate billing trap",
  "url": "https://urgent.news/2026/09/24/meta-ads-steered-polish-android-users-into-a-premium-rate-billing-trap",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T11:26:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/cyber-crime/2026/09/24/meta-ads-steered-polish-android-users-into-a-premium-rate-billing-trap/5298790"
  },
  "original_language": "en",
  "account": "Poland's Computer Emergency Response Team (CERT Polska) has uncovered a toll fraud campaign that employed paid Meta ads to direct Polish users towards malicious apps on Google Play. The investigation revealed 1,235 Meta ads, with 852 promoting 17 apps connected to the operation. Six of these ads contained confirmed toll fraud components or direct links to them, while the remaining 11 shared malicious loaders. Toll fraud involves malware enrolling mobile subscribers in paid services without their consent, often through premium-rate SMS or automated carrier billing. CERT identified two billing routes, with charges ranging from 17 PLN ($4.41) per week to 30.75 PLN ($7.97) per message. Three specific short codes and a separate carrier billing offer operated by Teleaudio were linked to the campaign. The investigation started with two fraudulent Facebook ads warning users about expired PDF applications, which led to the Google Play listing for Messenger Pro, an SMS app containing the malicious loader. CERT subsequently discovered nine TikTok ads promoting another app from the campaign, although the hidden code followed a different path. The operation leveraged both Meta and Google Play, with Meta providing paid acquisition to Polish users and Google Play serving as the installation path. Messenger Pro functioned as an SMS app and could request to become the device's default message handler, while its base APK reconstructed an encrypted DEX file at runtime. The loader checked the package name and mobile country code, contacted a policy server, decrypted another DEX, and downloaded the final fraud payload from Alibaba Cloud Object Storage Service. CERT reported the malicious app to Google on September 15 and reported all uncovered apps to Google. Google removed the identified apps from Play, while Meta took down the ads reported. The command-and-control infrastructure remained active, issuing jobs to controlled Polish registrations, and new packages appeared after Google removed the reported apps.",
  "summary": "CERT Polska linked 852 promotions to 17 Google Play apps capable of sending costly texts or starting recurring subscriptions",
  "key_points": [
    "Meta ads directed 1,235 ads at Polish users to malicious apps on Google Play.",
    "Six ads contained confirmed toll fraud components or direct links to them.",
    "CERT reported malicious apps to Google on September 15, leading to removal from Play."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Meta ads steered Polish Android users into a premium-rate billing trap",
        "url": "https://urgent.news/2026/09/24/meta-ads-steered-polish-android-users-into-a-premium-rate-billing-trap-9546941",
        "published": "2026-09-24T11:26:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}