Android ‘Toll Fraud’ Malware Detected, Subscribes Users to Premium Services Without Consent

The malware is largely distributed outside of Google Play because Google restricts the use of dynamic code loading by apps.

Advertisement
By Gadgets 360 Staff With Inputs From ANI | Updated: 4 July 2022 14:11 IST
Highlights
  • The apps harbouring the malware use "dynamic code loading"
  • The malware subscribes users to a premium service
  • The malware is largely distributed outside of Google Play

The apps harbouring the malware are usually classified as "toll fraud"

Photo Credit: Reuters

American tech giant Microsoft's 365 Defender Team recently revealed the growing popularity of malware that can subscribe users to a premium service without their knowledge.

In a blog post, the team explains that the attack from this form of malware is quite elaborate, while detailing the steps that the malware executes after infecting a device.

Advertisement

The apps harbouring the malware are usually classified as "toll fraud" and use "dynamic code loading" to carry out the attack, according to Microsoft.

The malware subscribes users to a premium service using their telecom provider's monthly bill which they are then forced to pay. It works by exploiting the WAP (wireless application protocol) used by cellular networks. That's why some forms of malware disable your Wi-Fi or just wait for you to go outside of Wi-Fi coverage.

Advertisement

This is where the aforementioned dynamic code loading comes into play. The malicious software then subscribes you to a service in the background, reads an OTP (one-time-password) you may receive before subscribing, fills out the OTP field on your behalf and hides the notification to cover its tracks.

The saving grace is that the malware is largely distributed outside of Google Play because Google restricts the use of dynamic code loading by apps, according to Microsoft.

Advertisement

Last month, cybersecurity platform Proofpoint discovered that the Emotet botnet — used by criminals to distribute malware around the world — has begun attempting to steal credit card information from unsuspecting users. The malware targets the popular Google Chrome browser, then sends the exfiltrated information to command-and-control servers.

The resurgence of the Emotet botnet comes over a year after Europol and international law enforcement agencies shut down the botnet's infrastructure in January 2021, and used the botnet to deliver software to remove the malware from infected computers.


What are the best tablets? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Instagram Might Be Testing a 'Plus' Subscription With These Features
  2. OnePlus Nord 6 Camera Configuration Revealed as India Launch Draws Near
  3. Lava Bold N2 Pro With 50-Megapixel Rear Camera Debuts in India: See Price
  4. Vivo Pad 6 Pro Launched With 13-2-Inch 4K Display and This Snapdragon Chip
  5. WhatsApp for CarPlay Reportedly Enters Beta Testing With These Features
  6. Google Pixel 11 Design, Key Specifications and Launch Timeline Leaked
  7. Vivo X300 Ultra, Vivo X300s Launched With Zeiss-Tuned Cameras and Teleconverter Support
  8. Xiaomi 18 Pro Max Might Feature a More Efficient 200-Megapixel Sensor
  9. Redmi Note 15 SE 5G to Launch With a Larger Battery Than Note 15 5G
  1. Google Warns Quantum Computers Could Crack Cryptographic Systems Sooner Than Expected
  2. Xiaomi 18 Pro Max Leak Points to New 200-Megapixel Sensor With Better Efficiency
  3. Redmi Note 15 SE 5G Confirmed to Launch in India With a Larger Battery Than Redmi Note 15 5G
  4. OnePlus Nord 6 Camera Configuration, Durability Details Revealed as India Launch Draws Near
  5. Instagram Plus Subscription Reportedly in Testing With Premium Story Tools, Exclusive Features
  6. WhatsApp Reportedly Testing Native CarPlay App With List of Recent Chats
  7. Bitcoin Price Hovers Around $67,000; Analysts Say Price Reflects Consolidation Phase
  8. Oppo Find X9 Ultra Global Launch Date Confirmed, Find X9s Pro Camera Details Teased Ahead of China Debut
  9. iOS 26.5 Beta 1 Rolls Out With Ads in Apple Maps, RCS Message Encryption Toggle
  10. Lava Bold N2 Pro Launched in India With 5,000mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.