ESPN DeportesChepo de la Torre: No pagamos el precio por ser los mejoresESPNRice bests Boone's belief by slugging homers 40, 41The Jerusalem PostIsrael Election 2026: What does Itamar Ben-Gvir's Otzma Yehudit stand for?InquirerEx-DPWH exec in Zaldy Co case to cite lack of equipment as defenseBollywood HungamaKaran Johar’s Rs. 480 crore jump: How he went from 5th to 4th on Hurun’s Bollywood Rich ListRTP DesportoDinis Ferreira vice-campeão do mundo de triatlo de junioresPunchJUST IN: Anthony Joshua, Tyson Fury to fight in Cardiff December 11Global NewsKenneth Law’s sentencing hearing to hear from more victims’ familiesWirtualna PolskaMetropolita przemyski apeluje o modlitwę w intencji ofiar z Jarosławian-tv"Es ist beängstigend": Ex-England-Stürmer Carroll: "Wurde sexuell missbraucht"CBS NewsTrump to host China's Xi at White House with AI and tariffs on the agendaRai NewsSalerno, 20enne accoltellata alle spalle da uno sconosciuto mentre cammina per strada
The Daily Newsstand · Free, Always
Thursday, September 24, 2026

Meta ads steered Polish Android users into a premium-rate billing trap

Translate

CERT Polska linked 852 promotions to 17 Google Play apps capable of sending costly texts or starting recurring subscriptions

Poland's Computer Emergency Response Team (CERT Polska) has disrupted an Android toll fraud campaign that used paid Meta ads to steer Polish users toward malicious apps on Google Play.

Its investigation documented 1,235 Meta ads, 852 of which promoted 17 apps tied to the operation. Six contained confirmed toll fraud components or direct links to them; the other 11 shared malicious loaders, although researchers could not recover their final payloads.

Toll fraud uses malware to enroll mobile subscribers in paid services without their informed consent. Depending on the provider, the malware may send a premium-rate SMS or automate a carrier billing flow, including intercepting the verification code needed to approve a subscription. The charges then appear on the victim's phone bill or are deducted from their prepaid balance.

REG AD

In one observed route, the malware sent generated keywords to premium-rate SMS short codes – abbreviated numbers used for paid services – to request or confirm a purchase. CERT checked three such numbers against the Polish telecom regulator UKE's public register and found that all were active premium services.

REG AD

The campaign supported two billing routes. The three registered short codes charged 30.75 PLN ($7.97) per message, while a separate direct-carrier billing offer operated by Teleaudio advertised a recurring charge of 17 PLN ($4.41) every seven days.

Kacper Ratajczak, senior security engineer at CERT Polska, did not disclose how many people were affected or their total losses. The three short codes were registered for use across Poland's four major mobile operators: Orange, T-Mobile, Play, and Polkomtel.

The investigation began with two Facebook ads falsely warning Polish users that their PDF application had expired. Clicking either ad opened the Google Play listing for Messenger Pro, an unrelated SMS app containing the malicious loader.

CERT later found nine TikTok ads promoting another app from the same advertising campaign, although its hidden code followed a different path and was not attributed to the same malware implementation.

"The operation relied on both platforms at once," said Ratajczak. "Meta supplied paid acquisition aimed at Polish users: advertisements placed inside a familiar feed carry the credibility of the advertising platform itself, so the false PDF warnings looked like ordinary product promotion. Google Play supplied the installation path that users treat as reviewed and trustworthy."

Messenger Pro functioned as an SMS app and could legitimately ask to become the device's default message handler. Behind that cover, its base APK reconstructed an encrypted DEX file at runtime.

The loader checked the package name and the device's mobile country code, contacted a policy server, and decrypted another DEX responsible for selecting and downloading the final fraud payload from Alibaba Cloud Object Storage Service.

Once running, the final payload contacted its command-and-control server, which assigned premium SMS or browser-based carrier billing jobs according to the victim's country and mobile operator.

REG AD

CERT reported Messenger Pro to Google on September 15 and subsequently reported every app uncovered during the investigation. Google removed the identified apps from Play, while Meta took down the ads reported by the researchers.

Removing the Play listings stopped new installations through those pages but did nothing to copies already installed. CERT said the command-and-control infrastructure remained operational during its analysis and continued issuing jobs to controlled Polish registrations.

Nor did the takedowns end distribution: CERT saw new packages appear after Google removed the apps it had reported. Anyone who installed one of the malicious apps therefore needs to remove it from their device. ®

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.