Researchers at Zimperium’s zLabs uncovered a large Android malware campaign that used nearly 250 malicious apps to silently subscribe victims to premium carrier-billing services and abuse premium SMS flows without consent. The apps impersonated well-known brands and games including Facebook Messenger, Instagram Threads, TikTok, Minecraft, and Grand Theft Auto, and targeted users in Malaysia, Thailand, Romania, and Croatia. The operation was active from March 2025 through January 2026, with some attacker infrastructure still online at the time of reporting.
zLabs identified three malware variants that activated only when a device’s SIM matched specific mobile operators, helping the fraud remain hidden from non-targeted users by showing benign fallback pages. The malware used hidden WebViews and JavaScript to automate subscription pages, intercepted one-time passwords through Google’s SMS Retriever API, disabled Wi‑Fi to force cellular billing, stole cookies, sent delayed premium SMS messages, and reported activity through attacker-controlled Telegram channels. Researchers said the infrastructure supported command-and-control, victim tracking, analytics, and exfiltration of device metadata and billing-page content.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On publication of its research, Zimperium disclosed the global Android fraud campaign and said parts of the attacker infrastructure were still operational. The company described the distributed infrastructure supporting command and control, victim tracking, analytics, and exfiltration of device and billing-page data.
Researchers reported that the malware campaign was still active through the second week of January 2026. They identified three malware variants, including one tailored to Thai users and another that sent operational updates to attacker-controlled Telegram channels.
From March 2025 through the second week of January 2026, the operation used nearly 250 malicious Android apps to target users in Malaysia, Thailand, Romania, and Croatia. The malware selectively activated based on the victim's SIM operator and used hidden WebViews, OTP interception, Wi‑Fi disabling, cookie theft, premium SMS abuse, and Telegram-based reporting to complete fraudulent subscriptions.
Zimperium's zLabs first observed a large Android malware operation in March 2025. The campaign used malicious apps posing as popular brands to target users for unauthorized carrier-billing and premium SMS charges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourceeconomictimes.indiatimes.com
Open sourcezimperium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.