Tollfraud Execution Flow | Image: CERT Polska
At a Glance
| Attribute | Details |
|---|---|
| Malware Family | Android Toll Fraud family (including Messenger Pro and AqMu builds) |
| Threat Actor | Unknown (unconfirmed attribution) |
| Target Victims | Android users across Poland, France, China, and 12 other countries |
| Delivery Vector | Deceptive Meta Facebook advertisements redirecting to Google Play listings |
| Key Capabilities | Multi-stage in-memory DEX execution, background WebView billing, premium SMS theft |
| Source | CERT Polska |
Executive Summary
CERT Polska uncovered a coordinated fraud campaign that pushed Google Play Android toll fraud malware through deceptive Facebook advertisements. The malicious applications posed as legitimate SMS clients and cleanup utilities. Behind this front, the software secretly opened carrier billing portals and subscribed users to expensive services. Consequently, the scheme added unwanted recurring charges directly to subscribers’ mobile phone bills.
Delivery and Malicious Advertising Tactics
The campaign relied heavily on paid social media promotions to attract victims. Specifically, investigators tracked 1,235 unique advertisements across 74 account profiles on Meta platforms. Among these, 852 advertisements promoted 17 separate applications linked to the same operation. The advertisements displayed fake warning messages stating that the user’s PDF viewer had expired.
The deceptive text warned users: “Your PDF application has expired. If you do not update now, you will no longer be able to open PDF files.” When users tapped the advertisement, the link redirected them to Google Play. However, the store listing presented an unrelated SMS application named Messenger Pro. As CERT Polska noted, “Both ads redirected users to the Google Play listing for Messenger Pro, where the unrelated SMS application could be installed.”
Infection Chain Architecture
The Android toll fraud malware used a modular four-stage infection process to evade static analysis. First, the base application package contained an encrypted executable container hidden inside its code files. Remarkably, the malware did not wait for the user to open the application. An exported Bluetooth Message Access Profile provider started the application process immediately after installation.
During startup, the base loader decrypted the first stage into memory. This stage validated the device’s mobile country code against an allowlist covering 15 nations. Next, the script contacted a remote policy server to retrieve dynamic routing instructions. The server response specified which malicious module the device should download.
Then, the secondary stage fetched a compressed archive from Alibaba Cloud Object Storage. The application decompressed this archive and loaded the final payload directly into memory using dynamic class loaders. By executing all code stages in memory, the malware prevented security scanners from inspecting the final payload files on disk.
The Default SMS Permission Disguise
The application used a clever disguise to obtain critical system privileges. Because Messenger Pro functioned as a real SMS tool, it legitimately requested to become the default messaging handler. Once the user approved this request, Android granted full permissions to read, receive, and send SMS messages. As researchers highlighted, “The app worked as a messenger and could legitimately ask to become the default SMS handler.” The malware then abused these messaging permissions to approve paid subscriptions.
Command-and-Control and Billing Automation
The core objective of the operation was financial theft through unauthorized mobile billing. As the research team explained, “Toll fraud is a form of mobile billing abuse in which malware enrolls a subscriber in a paid service without informed consent.” The malware contacted its command server over cleartext web requests. It generated random URL paths and encrypted request bodies using deterministic keys.
The server assigned two distinct fraud routines based on the device’s mobile network. In the premium SMS path, the command server delivered short codes and keywords to the device. The application then sent background text messages to Polish numbers such as 92505, 92512, and 92513. Regulatory records from Poland’s Office of Electronic Communications confirmed that each message incurred a gross charge of 30.75 PLN.
Alternatively, the malware used direct carrier billing through an invisible web browser component. It requested a dedicated cellular network connection to ensure that the mobile operator could identify the subscriber. Next, the hidden browser loaded payment pages from services like Teleaudio. Remote scripts entered the subscriber’s phone number and intercepted incoming verification PIN codes before closing the dialog. One captured workflow enrolled victims into recurring subscriptions costing 17 PLN every seven days.
Attribution Analysis
CERT Polska evaluated the operation’s technical infrastructure but reached no definitive attribution. Investigators observed shared registration data across 20 server domains registered between July and September 2026. Furthermore, multiple servers presented an expired security certificate linked to previous malicious campaigns. Despite these technical connections, CERT Polska concluded: “We therefore make no attribution concerning the operator’s identity, nationality or location.”
Defense and Detection Guidance
Following notifications from CERT Polska, Google removed all identified applications from the Google Play store. Additionally, Meta took down the fraudulent advertising profiles. However, users who already installed these applications remain vulnerable until they remove them manually.
Mobile users should inspect their devices for unrecognized messaging or utility applications. Check your default SMS application settings and revoke permissions from suspicious tools. Furthermore, review your monthly mobile carrier statements for unexpected premium charges or subscription fees. Subscribers can also contact their mobile providers to block premium-rate text messages and direct carrier billing.
Organizations should configure mobile device management policies to restrict installations from unknown developers. To inspect technical indicators and package names, review the CERT Polska technical report on Android toll fraud. Staying vigilant against urgent update warnings remains essential to prevent mobile fraud.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!