deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

CERT Polska maps 1,235-ad malvertising chain behind Android toll fraud

CERT Polska traced a toll fraud operation from two Facebook ads to 1,235 Meta ads under 74 profile names, and found takedowns by Google and Meta left the command-and-control servers running.

CERT Polska maps 1,235-ad malvertising chain behind Android toll fraud

From two ads to 1,235

CERT Polska's investigation, published on 23 September 2026, opened with two Facebook advertisements recorded on 14 September. Both pushed the same fake “PDF update” theme, and both pointed to the Google Play listing for Messenger Pro, a messaging app with nothing to do with PDF files. Working outward from that pair, the analysts assembled 1,235 unique Meta ad records, 74 identified profile names and 29 Google Play applications.

According to CERT Polska, the case exposes a weakness on the distribution side that app and ad review never addressed: the advertisements were ordinary promotional content rather than malicious files, and the applications worked as messengers and utilities. The fraud lived in hidden code paths that neither a store listing nor an ad review would surface.

Evidence sorted by strength

The analysts grouped their findings by how strong the link was. Samples with a confirmed toll fraud module accounted for 532 ads under 28 named profiles. Another 320 ads across 33 profiles led to apps carrying a related loader whose final payload was never recovered. Smaller tiers covered ads tied only by a reused advertiser profile (98), the same campaign with a different app implementation (94), ads already removed (90), apps whose APKs could not be obtained (82), and identical ad assets without a confirmed loader (19).

The exclusions matter as much as the inclusions. Quick Show and BlushToon ran 98 ads under profiles that also promoted confirmed campaign software, but their APKs were comic readers built on different code and infrastructure, so they were dropped. Profile names, CERT Polska stresses, are display labels attached to ads, not verified identities.

Identical ad files as connective tissue

The operation recycled its advertising material heavily. Beyond the initial set, the analysts collected 898 further ad files and sorted them into 45 groups sharing identical SHA-256 hashes; 23 of those groups matched files from the first collection. One unchanged file turned up in 55 new ads spanning 20 packages and 39 identified profiles; another grew from 26 ads to 50. Byte-identical files spread across dozens of supposedly separate advertisers point to one team preparing the material rather than unrelated copycats.

Fifty-nine low-reputation display names carried the traffic. The busiest included Britney Harris with 62 ads, Joshua Wilson with 55, James Davis with 42, Sarah Anderson with 36 and Mary Garcia with 33.

The seventeen apps behind the ads

Seventeen applications, promoted through 852 ads under 60 profile names, were tied to the operation by code or infrastructure evidence. Nine stand out: Cool Wallpaper (153 ads, confirmed toll fraud), Text Chat (135, confirmed), Seed Text Messages (133, confirmed loader), Max Messenger (121, confirmed), Instant Messages (99, loader), Colorful Message (94, same ad campaign but a different hidden code path), Messenger Pro (49, confirmed), Phone Cleaner Master (40, confirmed) and PDF Scanner Art (34, confirmed). Eleven further APKs carried loaders connected through ad destinations, concealed components, activation behaviour and shared infrastructure; their fraud modules were never recovered, and the report keeps that evidence tier separate. Colorful Message was also promoted in nine ads found separately on TikTok.

Takedowns that stop short

Google removed the reported applications and Meta removed the reported ads, but both actions were inherently partial: they covered only what the analysts had identified. Other ads in the operation may have kept running or expired on their own, and the command-and-control infrastructure was still answering after the store removals. CERT Polska sets this against an earlier assessment from March 2025, which found Meta had not acted on several proposed safeguards, including better handling of ordinary user reports, proactive blocking of returning advertisers, and integration with the CERT Polska Warning List.

Almost no shadow in service data

A dev.to write-up summarising the report also probed the backend layer with ZoomEye queries run on 24 September 2026. The cloud storage domain the operation relied on, aliyuncs.com, matched 1,995 indexed services, while the campaign's own domains returned zero matches. Its IP addresses fared little better: 38, 10, five and two matching services across the four addresses checked. The narrow conclusion is that an operation of this size leaves almost no service-level trace of its own endpoints while renting infrastructure from a ubiquitous cloud brand.

Why it matters

The investigation shows that distribution, not payload, is the scalable half of mobile fraud: functional apps and clean ad creative pass review, so file-focused defenses miss the campaign entirely. The practical takeaways are concrete: cluster ad creatives by hash, treat advertiser profiles that reappear across unrelated apps as a signal, and assume store removal does not disable command-and-control servers. The report is also candid about its limits: the 1,235 ads are what could be recovered and verified rather than the campaign's full output, no impression or reach figures were published, and no attribution is offered.

  • #malvertising
  • #android
  • #toll-fraud
  • #security
  • #google-play

Related posts