CERT Polska Links 20 Malicious Android Apps via Shared TLS Certificate and DNS Patterns
CERT Polska's September 23, 2026 report details an investigation into a mobile toll fraud campaign that connected 20 applications through infrastructure evidence rather than malware code similarity. Six apps were confirmed to contain toll fraud components or direct payload links, while eleven others carried malicious loaders tied to the same operation through shared ad destinations and activation logic. A single reused Let's Encrypt certificate, observed across five independently recovered server addresses, served as a key linking artifact across the campaign's infrastructure. Additional connections included automated domain registration through Amazon Registrar within a narrow two-month window, shared WHOIS field hashes across multiple parent domains, and identical C2 fallback addresses embedded in separate app versions. The report carefully distinguishes confirmed participants from apps that merely reused advertiser accounts, noting that two comic-reader apps showed account reuse but not direct involvement in the fraud operation.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in