Android ‘Toll Fraud’ Malware Detected, Subscribes Users to Premium Services Without Consent

The malware is largely distributed outside of Google Play because Google restricts the use of dynamic code loading by apps.

Advertisement
By Gadgets 360 Staff With Inputs From ANI | Updated: 4 July 2022 14:11 IST
Highlights
  • The apps harbouring the malware use "dynamic code loading"
  • The malware subscribes users to a premium service
  • The malware is largely distributed outside of Google Play

The apps harbouring the malware are usually classified as "toll fraud"

Photo Credit: Reuters

American tech giant Microsoft's 365 Defender Team recently revealed the growing popularity of malware that can subscribe users to a premium service without their knowledge.

In a blog post, the team explains that the attack from this form of malware is quite elaborate, while detailing the steps that the malware executes after infecting a device.

The apps harbouring the malware are usually classified as "toll fraud" and use "dynamic code loading" to carry out the attack, according to Microsoft.

Advertisement

The malware subscribes users to a premium service using their telecom provider's monthly bill which they are then forced to pay. It works by exploiting the WAP (wireless application protocol) used by cellular networks. That's why some forms of malware disable your Wi-Fi or just wait for you to go outside of Wi-Fi coverage.

Advertisement

This is where the aforementioned dynamic code loading comes into play. The malicious software then subscribes you to a service in the background, reads an OTP (one-time-password) you may receive before subscribing, fills out the OTP field on your behalf and hides the notification to cover its tracks.

The saving grace is that the malware is largely distributed outside of Google Play because Google restricts the use of dynamic code loading by apps, according to Microsoft.

Advertisement

Last month, cybersecurity platform Proofpoint discovered that the Emotet botnet — used by criminals to distribute malware around the world — has begun attempting to steal credit card information from unsuspecting users. The malware targets the popular Google Chrome browser, then sends the exfiltrated information to command-and-control servers.

The resurgence of the Emotet botnet comes over a year after Europol and international law enforcement agencies shut down the botnet's infrastructure in January 2021, and used the botnet to deliver software to remove the malware from infected computers.


What are the best tablets? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival 2025 Sale Will Begin on This Date
  2. Flipkart Big Billion Days Sale Date Revealed, Will Compete With Amazon Sale
  3. Top OTT Releases of the Week (Sept 1 - Sept 7): Know What to Watch
  4. Tecno Pova Slim 5G Launched in India With 5.95mm Thin Profile: See Price
  5. Lunar Eclipse 2025: Will People in India Be Able to See the Blood Moon?
  6. Vivo X300 Pro Might Not Arrive With Faster Charging Support
  7. Samsung Galaxy S25 FE Launched With Exynos 2400 SoC: See Price
  8. Jio Announces Rs. 349 Celebration Plan With Free Vouchers Worth Rs. 3,000
  9. Instagram Has Finally Launched an Optimised Version of Its App for iPad
  10. NASA Tracks Newly Discovered Bus-Sized Asteroid as It Flies Past Earth
  1. ISRO Tests Parachutes for Gaganyaan Crew Module in Key Rocket-Sled Trial
  2. India’s PRATUSH Computer Could Detect Signals From the Universe’s First Stars: Report
  3. NASA Tracks Newly Discovered Bus-Sized Asteroid as It Flies Past Earth
  4. Ashneer Grover’s Rise and Fall to Premiere on OTT Soon: All the Details
  5. Dyson PencilVac Unveiled Alongside 10 New Floor Cleaners, Air Purifiers and Hair Dryers at IFA 2025
  6. NASA's Hubble Captures Interstellar Comet 3I/ATLAS Ahead of Close Mars Flyby
  7. Raju Jeyamohan-Starrer Bun Butter Jam to Stream on OTT Soon: Know When, Where to Watch Online
  8. Kannappa Now Streaming Online: Know When and Where to Watch This Vishnu Manchu-Starrer Online
  9. NASA’s James Webb Space Telescope Spots Rare Quintet of Galaxies From the Early Universe
  10. Lunar Eclipse September 2025: Know Who Will Get to See the Blood Moon on September 7
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.