Back
CERT Polska: Meta ads steered Polish Android users into a premium-rate billing trap
SiTech AI Team2 წთ. საკითხავი

CERT Polska: Meta ads steered Polish Android users into a premium-rate billing trap

CERT Polska has documented an Android toll fraud operation in which 1,235 paid Meta ads pushed Polish users to malicious Google Play apps, while hidden code silently triggered premium SMS charges and recurring carrier billing.

Poland's CERT Polska has documented an Android toll fraud operation that used paid ads on Meta's platforms to steer Polish users toward malicious apps on Google Play. Its investigation preserved 1,235 Meta ads; 852 of them, published under 60 displayed profile names, promoted 17 Play apps tied to the operation by code or infrastructure.

The fake Facebook ad claiming a PDF app had expired

From two ads to a campaign

The probe began on 14 September with two Facebook ads that falsely warned users their PDF application had expired. Clicking either opened the Google Play listing for Messenger Pro, an SMS app unrelated to PDF files. According to CERT Polska, it worked as a messenger and could legitimately ask to become the device's default SMS handler, but behind that cover it rebuilt an encrypted module, checked the SIM's mobile country code (MCC 260 for Poland) and downloaded the final fraud payload. Six of the 17 apps carried confirmed toll fraud components or direct payload links; the other 11 held malicious loaders.

How the billing trap worked

Toll fraud enrolls subscribers in paid services without informed consent. CERT Polska saw two routes. The first sent generated keywords to premium-rate SMS short codes charging 30.75 PLN ($7.97) per message; all three numbers used — 92505, 92512 and 92513 — were active premium services in the register of Poland's regulator UKE and worked across all four major operators: Orange, T-Mobile, Play and Polkomtel. The second automated a browser-based carrier billing flow, intercepting the verification text too, and reached a Teleaudio offer of 17 PLN ($4.41) every seven days.

CERT Polska's senior security engineer, Kacper Ratajczak, said the operation relied on both platforms at once: "ads inside a familiar feed carry the credibility of the platform itself, so the false PDF warnings looked like ordinary promotion, while Google Play supplied the installation path users treat as trustworthy." He did not disclose how many people were affected or the total losses.

Takedowns and residual risk

CERT Polska reported Messenger Pro to Google on 15 September; Google removed that app and the others uncovered later, and Meta took down the ads the researchers reported. The removals stopped new installations through those listings but did nothing about copies already installed: CERT said the command-and-control infrastructure stayed active and kept assigning jobs, and new packages appeared after the takedowns. Users who installed one of the affected apps should uninstall it.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.