Researchers at Zimperium’s zLabs uncovered a large Android malware campaign that used nearly 250 malicious apps to silently subscribe victims to premium carrier-billing services and abuse premium SMS flows without consent. The apps impersonated well-known brands and games including Facebook Messenger, Instagram Threads, TikTok, Minecraft, and Grand Theft Auto, and targeted users in Malaysia, Thailand, Romania, and Croatia. The operation was active from March 2025 through January 2026, with some attacker infrastructure still online at the time of reporting.
zLabs identified three malware variants that activated only when a device’s SIM matched specific mobile operators, helping the fraud remain hidden from non-targeted users by showing benign fallback pages. The malware used hidden WebViews and JavaScript to automate subscription pages, intercepted one-time passwords through Google’s SMS Retriever API, disabled Wi‑Fi to force cellular billing, stole cookies, sent delayed premium SMS messages, and reported activity through attacker-controlled Telegram channels. Researchers said the infrastructure supported command-and-control, victim tracking, analytics, and exfiltration of device metadata and billing-page content.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
On publication of its research, Zimperium disclosed the global Android fraud campaign and said parts of the attacker infrastructure were still operational. The company described the distributed infrastructure supporting command and control, victim tracking, analytics, and exfiltration of device and billing-page data.
Researchers reported that the malware campaign was still active through the second week of January 2026. They identified three malware variants, including one tailored to Thai users and another that sent operational updates to attacker-controlled Telegram channels.
From March 2025 through the second week of January 2026, the operation used nearly 250 malicious Android apps to target users in Malaysia, Thailand, Romania, and Croatia. The malware selectively activated based on the victim's SIM operator and used hidden WebViews, OTP interception, Wi‑Fi disabling, cookie theft, premium SMS abuse, and Telegram-based reporting to complete fraudulent subscriptions.
Zimperium's zLabs first observed a large Android malware operation in March 2025. The campaign used malicious apps posing as popular brands to target users for unauthorized carrier-billing and premium SMS charges.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceeconomictimes.indiatimes.com
Open sourcezimperium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.