CERT Polska's investigation documented 1,235 Meta ads, of which 852 promoted 17 apps linked to the operation. Six of those apps contained confirmed toll fraud components, while the other 11 shared malicious loaders. Toll fraud malware enrolls mobile subscribers in paid services without their consent by sending premium-rate SMS messages or automating carrier billing flows, including intercepting verification codes.
The campaign used two billing routes: three registered premium SMS short codes charging 30.75 PLN ($7.97) per message, and a separate direct-carrier billing offer from Teleaudio with a recurring charge of 17 PLN ($4.41) every seven days. The short codes were registered for use across Poland's four major mobile operators: Orange, T-Mobile, Play, and Polkomtel.
The investigation began with two Facebook ads falsely warning users that their PDF application had expired. Clicking either ad led to the Google Play listing for Messenger Pro, an unrelated SMS app containing the malicious loader. CERT also found nine TikTok ads promoting another app from the same campaign, though its hidden code took a different path.
"The operation relied on both platforms at once," said Kacper Ratajczak, senior security engineer at CERT Polska. "Meta supplied paid acquisition aimed at Polish users: advertisements placed inside a familiar feed carry the credibility of the advertising platform itself, so the false PDF warnings looked like ordinary product promotion. Google Play supplied the installation path that users treat as reviewed and trustworthy."
Messenger Pro functioned as an SMS app and could legitimately request to become the device's default message handler. Behind the scenes, its base APK reconstructed an encrypted DEX file at runtime. The loader checked the package name and device's mobile country code, contacted a policy server, and decrypted another DEX that selected and downloaded the final fraud payload from Alibaba Cloud Object Storage Service. Once running, the payload contacted its command-and-control server, which assigned premium SMS or browser-based carrier billing jobs based on the victim's country and mobile operator.
CERT reported Messenger Pro to Google on September 15 and subsequently reported every app uncovered. Google removed the identified apps from Play, and Meta took down the ads. However, removal from Play stopped new installations but did not affect copies already installed. CERT noted that the command-and-control infrastructure remained operational during its analysis and continued issuing jobs to controlled Polish registrations. New packages appeared after Google removed the reported apps, indicating ongoing distribution. Anyone who installed a malicious app must remove it from their device.
Ratajczak did not disclose the number of affected users or total losses.