On 14 September, CERT Polska found two Facebook advertisements warning Polish users that their PDF application had expired. Both linked straight to Google Play, and to an app called Messenger Pro that has nothing to do with PDF files. It worked as a messenger, and it could reasonably ask to become the phone's default SMS handler. Behind that cover, it was signing the handset up to paid subscription services the owner never asked for.
What started as two advertisements turned out to be an operation. In an analysis published this week, CERT Polska's Kacper Ratajczak describes 1235 preserved Meta advertisements posted under 74 profile names. Of those, 852 ads under 60 names promoted 17 Google Play applications tied back to the same operation through shared code or shared infrastructure.
A messenger that answers the bill for you
The scheme is called toll fraud: billing abuse in which malware enrolls a subscriber in a paid service without informed consent. Messenger Pro's installed package rebuilt an encrypted block of code, which pulled data from a server and decrypted a second block. That layer applied a country policy and downloaded the fraud payload. The stage that costs the victim money never sits in the app Google reviewed.
Poland, identified by mobile country code 260, was routed to the default payload. During a controlled run the command and control server handed out both premium SMS jobs and browser based carrier billing jobs. Server supplied JavaScript triggered an sms: link with no user gesture at all. The billing page and the confirmation message need never appear on screen.
The regulator's own register named the numbers
Three short codes came back from that server: 92505, 92512 and 92513. CERT Polska checked them against the UKE Rejestr Premium, the Polish regulator's public list of premium rate numbers, and all three were active registered services at a gross price of 30.75 PLN per message, carried across Orange, T-Mobile, Play and Polkomtel. The registered service names match the keywords the malware was sending. A separate job reached a Teleaudio page advertising 17 PLN every seven days, billed directly by the carrier. CERT Polska is explicit that the companies registered to those numbers are billing aggregators whose services were abused, not the people running the campaign.
Pulling the listing did not stop it
CERT Polska reported Messenger Pro to Google on 15 September and Google removed it. That closed off new installations through the listing and did nothing about copies already on phones. The command and control infrastructure stayed up throughout the analysis, still accepting controlled Polish registrations and still issuing jobs after the app had gone from the store.
Check the bill, not just the app drawer
Anyone who installed one of these apps has to remove it by hand. Check recent operator charges for premium SMS and subscription entries, and ask the carrier to block premium rate services on the number. Treat a request to become the default SMS handler as a serious permission whatever the app claims to be. Indicators include the package name com.messages.sms.messenger.textmessage.owyo and the servers 8[.]219[.]222[.]81 and 47[.]245[.]84[.]227. Our Poland country profile carries the national picture, and IntelFusions reported in August on banking trojans reaching Google Play inside dropper apps.
The lesson sits in the pairing rather than in either platform. Meta supplied paid reach into a feed people already trust, so a false warning about an expired PDF reader arrived carrying the advertising platform's own credibility. Google Play supplied an installation path users treat as reviewed. Neither had to be broken. Both simply had to be used exactly as intended.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.