Meta ads used to steer Polish Android users into premium-rate SMS scam

CERT Polska uncovers toll fraud campaign that used paid advertisements on Meta and TikTok to lure victims into downloading malicious apps from Google Play

By LineZotpaper
Published
Read Time3 min
Poland's Computer Emergency Response Team (CERT Polska) has disrupted an Android toll fraud campaign that leveraged paid Meta ads to direct Polish users to malicious apps on Google Play, with some victims charged up to $7.97 per premium SMS or recurring fees of $4.41 every seven days.

CERT Polska's investigation documented 1,235 Meta ads, of which 852 promoted 17 apps linked to the operation. Six of those apps contained confirmed toll fraud components, while the other 11 shared malicious loaders. Toll fraud malware enrolls mobile subscribers in paid services without their consent by sending premium-rate SMS messages or automating carrier billing flows, including intercepting verification codes.

The campaign used two billing routes: three registered premium SMS short codes charging 30.75 PLN ($7.97) per message, and a separate direct-carrier billing offer from Teleaudio with a recurring charge of 17 PLN ($4.41) every seven days. The short codes were registered for use across Poland's four major mobile operators: Orange, T-Mobile, Play, and Polkomtel.

The investigation began with two Facebook ads falsely warning users that their PDF application had expired. Clicking either ad led to the Google Play listing for Messenger Pro, an unrelated SMS app containing the malicious loader. CERT also found nine TikTok ads promoting another app from the same campaign, though its hidden code took a different path.

"The operation relied on both platforms at once," said Kacper Ratajczak, senior security engineer at CERT Polska. "Meta supplied paid acquisition aimed at Polish users: advertisements placed inside a familiar feed carry the credibility of the advertising platform itself, so the false PDF warnings looked like ordinary product promotion. Google Play supplied the installation path that users treat as reviewed and trustworthy."

Messenger Pro functioned as an SMS app and could legitimately request to become the device's default message handler. Behind the scenes, its base APK reconstructed an encrypted DEX file at runtime. The loader checked the package name and device's mobile country code, contacted a policy server, and decrypted another DEX that selected and downloaded the final fraud payload from Alibaba Cloud Object Storage Service. Once running, the payload contacted its command-and-control server, which assigned premium SMS or browser-based carrier billing jobs based on the victim's country and mobile operator.

CERT reported Messenger Pro to Google on September 15 and subsequently reported every app uncovered. Google removed the identified apps from Play, and Meta took down the ads. However, removal from Play stopped new installations but did not affect copies already installed. CERT noted that the command-and-control infrastructure remained operational during its analysis and continued issuing jobs to controlled Polish registrations. New packages appeared after Google removed the reported apps, indicating ongoing distribution. Anyone who installed a malicious app must remove it from their device.

Ratajczak did not disclose the number of affected users or total losses.

§

Analysis

Why This Matters

  • This campaign exploits the trust users place in both social media advertising and official app stores, showing how a two-platform attack can bypass typical safeguards.
  • Victims face financial loss through unauthorized charges on phone bills or prepaid balances, with limited recourse given the difficulty of tracing perpetrators.
  • The ongoing distribution despite takedowns highlights the challenge of fully disrupting such operations once they are established.

Background

Toll fraud is a persistent mobile threat that drains victims' funds by enrolling them in premium-rate services without consent. Historically, such scams relied on sideloaded apps or malicious links. This case is notable because it combines paid social media ads — which carry an implicit endorsement from the platform — with Google Play's official distribution channel, making the apps appear legitimate. CERT Polska is Poland's national CSIRT, responsible for responding to cyber threats affecting citizens and infrastructure.

Key Perspectives

CERT Polska: The campaign's reliance on both Meta ads and Google Play's distribution undermines user trust in both platforms. Researchers emphasize that aggressive ad review and app vetting are needed to prevent such abuses. Meta and Google: Both companies cooperated with takedown requests, removing the reported ads and apps. However, the reappearance of new packages after removals suggests their reactive measures may be insufficient against determined adversaries. Telecom regulators: The use of registered premium short codes and a licensed carrier billing provider indicates the fraud may exploit legitimate billing infrastructure, raising questions about oversight and reporting requirements for such services.

What to Watch

  • Whether new malicious apps or ads appear after the takedowns, indicating if the operation adapts.
  • Any updates from Google on changes to Play Store app review processes, especially for apps requesting SMS permissions.
  • Polish telecom regulator UKE's response regarding the premium-rate numbers and carrier billing provider Teleaudio.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.