Android Toll Fraud Campaign Used Fake Facebook Ads to Hijack Polish Phone Bills
On 14 September 2026, CERT Polska analysts identified two Facebook advertisements falsely claiming users' PDF apps had expired, directing them to install an unrelated app called Messenger Pro from Google Play. Once installed, the app executed a four-stage hidden payload chain that ultimately charged victims' mobile accounts without their knowledge. Despite appearing functional — with a working inbox and privacy assurances on its permission screen — the app quietly obtained SMS and phone-state permissions that the concealed code exploited for carrier billing fraud. Google was notified on 15 September 2026 and removed the app from the Play Store, though devices with existing installations remained at risk and the campaign's command-and-control infrastructure continued operating. The operation highlights how threat actors can abuse app store trust and system-granted permissions to turn legitimate-looking installs into financial fraud tools.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in