Researchers identified Fleckpe, an Android subscription Trojan distributed through 11 malicious apps on Google Play that masqueraded as photo editors, wallpaper tools, and similar utilities. Before Google removed the apps, they had accumulated more than 620,000 installs. The malware has reportedly been active since 2022 and was designed to monetize infections by silently enrolling victims in premium mobile services without their knowledge.
Fleckpe used a malicious dropper and a heavily obfuscated native library to decrypt and run its payload, then contacted command-and-control infrastructure and opened subscription pages in an invisible browser window. It also abused notification access to intercept confirmation messages and complete the sign-up flow automatically. Analysis indicated a particular focus on Thailand, based on hard-coded Thai MCC/MNC values and Thai-language reviews, although infections were also observed in Poland, Malaysia, Indonesia, and Singapore. Newer variants shifted more subscription logic into native code to complicate analysis and evade detection.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Kaspersky published a report detailing Fleckpe's use of an obfuscated native library, a malicious dropper, invisible browser-based subscription fraud, notification interception, and associated command-and-control domains and hashes.
Kaspersky reported that the Fleckpe Android subscription Trojan had likely been active since 2022, distributed through malicious Google Play apps disguised as utilities such as photo editors and wallpaper apps.
By the time of Kaspersky's report, all 11 identified Fleckpe-infected apps had been removed from Google Play. The report noted that additional undiscovered infected apps may also have existed.
Kaspersky identified 11 Google Play apps infected with Fleckpe that had accumulated more than 620,000 installs. The campaign particularly targeted Thailand, with additional victims observed in Poland, Malaysia, Indonesia, and Singapore.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 86 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.