Meta ads steered Polish Android users into a premium-rate billing trap

CERT Polska linked 852 promotions to 17 Google Play apps capable of sending costly texts or starting recurring subscriptions

Poland's Computer Emergency Response Team (CERT Polska) has disrupted an Android toll fraud campaign that used paid Meta ads to steer Polish users toward malicious apps on Google Play.

Its investigation documented 1,235 Meta ads, 852 of which promoted 17 apps tied to the operation. Six contained confirmed toll fraud components or direct links to them; the other 11 shared malicious loaders, although researchers could not recover their final payloads.

Toll fraud uses malware to enroll mobile subscribers in paid services without their informed consent. Depending on the provider, the malware may send a premium-rate SMS or automate a carrier billing flow, including intercepting the verification code needed to approve a subscription. The charges then appear on the victim's phone bill or are deducted from their prepaid balance.

In one observed route, the malware sent generated keywords to premium-rate SMS short codes – abbreviated numbers used for paid services – to request or confirm a purchase. CERT checked three such numbers against the Polish telecom regulator UKE's public register and found that all were active premium services.

The campaign supported two billing routes. The three registered short codes charged 30.75 PLN ($7.97) per message, while a separate direct-carrier billing offer operated by Teleaudio advertised a recurring charge of 17 PLN ($4.41) every seven days.

Kacper Ratajczak, senior security engineer at CERT Polska, did not disclose how many people were affected or their total losses. The three short codes were registered for use across Poland's four major mobile operators: Orange, T-Mobile, Play, and Polkomtel.

The investigation began with two Facebook ads falsely warning Polish users that their PDF application had expired. Clicking either ad opened the Google Play listing for Messenger Pro, an unrelated SMS app containing the malicious loader.

CERT later found nine TikTok ads promoting another app from the same advertising campaign, although its hidden code followed a different path and was not attributed to the same malware implementation.

Messenger Pro functioned as an SMS app and could legitimately ask to become the device's default message handler. Behind that cover, its base APK reconstructed an encrypted DEX file at runtime.

The loader checked the package name and the device's mobile country code, contacted a policy server, and decrypted another DEX responsible for selecting and downloading the final fraud payload from Alibaba Cloud Object Storage Service.

Once running, the final payload contacted its command-and-control server, which assigned premium SMS or browser-based carrier billing jobs according to the victim's country and mobile operator.

CERT reported Messenger Pro to Google on September 15 and subsequently reported every app uncovered during the investigation. Google removed the identified apps from Play, while Meta took down the ads reported by the researchers.

Removing the Play listings stopped new installations through those pages but did nothing to copies already installed. CERT said the command-and-control infrastructure remained operational during its analysis and continued issuing jobs to controlled Polish registrations.

Nor did the takedowns end distribution: CERT saw new packages appear after Google removed the apps it had reported. Anyone who installed one of the malicious apps therefore needs to remove it from their device. ®

Original source Meta ads steered Polish Android users into a premium-rate billing trap

Back to home