Android ‘Toll Fraud’ Malware Detected, Subscribes Users to Premium Services Without Consent

The malware is largely distributed outside of Google Play because Google restricts the use of dynamic code loading by apps.

Advertisement
By Gadgets 360 Staff With Inputs From ANI | Updated: 4 July 2022 14:11 IST
Highlights
  • The apps harbouring the malware use "dynamic code loading"
  • The malware subscribes users to a premium service
  • The malware is largely distributed outside of Google Play

The apps harbouring the malware are usually classified as "toll fraud"

Photo Credit: Reuters

American tech giant Microsoft's 365 Defender Team recently revealed the growing popularity of malware that can subscribe users to a premium service without their knowledge.

In a blog post, the team explains that the attack from this form of malware is quite elaborate, while detailing the steps that the malware executes after infecting a device.

The apps harbouring the malware are usually classified as "toll fraud" and use "dynamic code loading" to carry out the attack, according to Microsoft.

Advertisement

The malware subscribes users to a premium service using their telecom provider's monthly bill which they are then forced to pay. It works by exploiting the WAP (wireless application protocol) used by cellular networks. That's why some forms of malware disable your Wi-Fi or just wait for you to go outside of Wi-Fi coverage.

This is where the aforementioned dynamic code loading comes into play. The malicious software then subscribes you to a service in the background, reads an OTP (one-time-password) you may receive before subscribing, fills out the OTP field on your behalf and hides the notification to cover its tracks.

The saving grace is that the malware is largely distributed outside of Google Play because Google restricts the use of dynamic code loading by apps, according to Microsoft.

Advertisement

Last month, cybersecurity platform Proofpoint discovered that the Emotet botnet — used by criminals to distribute malware around the world — has begun attempting to steal credit card information from unsuspecting users. The malware targets the popular Google Chrome browser, then sends the exfiltrated information to command-and-control servers.

The resurgence of the Emotet botnet comes over a year after Europol and international law enforcement agencies shut down the botnet's infrastructure in January 2021, and used the botnet to deliver software to remove the malware from infected computers.


What are the best tablets? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Madharaasi OTT Release Date: When and Where to Watch To Stream Sivakarthikeyan's Online
  2. Oppo A6 5G With 7,000mAh Battery Launched: Check Price, Features
  3. iPhone 17 Pro Max Review: A Supercar Engine in Your Pocket
  4. Samsung Galaxy Tab A11+ With 7,040mAh Battery Launched
  5. First Look at the Honor Magic 8 Pro Revealed via Hands-On Images
  6. iQOO 15 Could Feature This Display, Cameras, Battery
  7. Pawan Kalyan's They Call Him OG OTT Release Reportedly Revealed: What You Need to Know
  8. Apple Fixes Bluetooth, Cellular and Other Issues With Latest Update
  1. Expedition 73 Astronauts Conduct Physics Experiments, Health Research, and Tech Tests on ISS
  2. Scientists May Finally Explain Mysterious Crown-Like Features on Venus
  3. Firefly Aerospace’s Alpha Rocket Explodes During Ground Preflight Test
  4. Lightweight AI Framework Boosts Speed and Accuracy of UAV Remote Sensing Object Detection
  5. Bridgerton Season 4 OTT Release Revealed: Know Everything About Plot, Streaming Platform, Cast, and More
  6. 13th OTT Release Date Revealed: Know Everything About This Drama Series
  7. Madharaasi OTT Release Date: When and Where to Watch To Stream Sivakarthikeyan Starrer Online
  8. Pawan Kalyan’s They Call Him OG OTT Release Reportedly Revealed: What You Need to Know
  9. Priyanka Kumar’s Doora Theera Yaana Now Streaming on SunNXT: Cast, Plot, and Reception
  10. Jay Kelly OTT Release Date: When and Where to Watch This George Clooney Starrer Movie
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.