Skip to content

Build1 publisher3 min readPublished

CERT Polska ties 17 Google Play apps and 852 Meta ads to one Android toll-fraud operation

CERT Polska tied 17 Google Play apps and 852 Meta ads to one Android toll-fraud operation aimed at Polish users. Its billing code arrived after install from an object-storage bucket. The public ad records told analysts more than the store listing did.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying CERT Polska ties 17 Google Play apps and 852 Meta ads to one Android toll-fraud operation
Generated illustration

What happened

  • The two ads recorded on 14 September warned that a PDF app had expired and sent users straight to Messenger Pro, a Google Play messaging app with no PDF function.
  • CERT Polska's wider dataset held 1,235 Meta ad records under 74 profile names, promoting 29 Google Play apps in total.
  • Setting Messenger Pro as the default SMS app made Android grant READ_SMS, RECEIVE_SMS, RECEIVE_MMS and SEND_SMS under the GRANTED_BY_ROLE flag.
  • Google pulled the app after CERT Polska's 15 September report, but installed copies stayed put and the operation's C2 kept answering test registrations from Poland.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Anyone who installed before the takedown still holds an app with SMS-send rights talking to live infrastructure. The store removal protected only people who had not yet installed it.
  • decision For mobile defenders, an app from an unrelated ad asking for the default-SMS role is a stronger signal than store approval. That one role grant supplied the permissions the billing code reused.
  • capability Public ad records joined with code and infrastructure evidence let an outside team tie 60 profile names to one operation. That lets a campaign be tracked across listings as they are replaced.

Almost all of Messenger Pro was a real messenger. In CERT Polska's test environment it finished onboarding and showed a working inbox with spam blocking and an archive [9]. Its permission screen read "Your privacy comes first. No unnecessary permissions." [9] The hidden code sat in classes9.dex, which held 0.552% of the app's 39,990,208 bytes of DEX code [11]. That is roughly 221 KB [1].

From that file, the chain ran in four steps [3]:

1. A single injected call in Application.onCreate() started the loader [12]. 2. The loader rebuilt stage 1, 80,384 bytes, as a byte array and loaded it with InMemoryDexClassLoader [12][14]. 3. Stage 1 checked the package and the country, then decrypted the 21,860-byte stage 2 the same way [12][14]. 4. Stage 2 chose a payload, downloaded the final DEX from an object-storage bucket and loaded it in memory [12]. Poland and other allowed mobile country codes got a 174,916-byte default payload. MCC 208 and 460 got a 216,724-byte one [14].

The user never had to open the app. The Package Manager registered the install at 12:54:02 on 15 September [13]. One second later the Android contacts process queried the app's exported Bluetooth Message Access Profile content provider [13]. ActivityManager started the app's process to answer, and startup reached Application.onCreate() and the injected call [13].

The write-up does not describe what Google's review examined before the listing went live. It does show what the published package held. The billing code was not in it, because stage 2 fetched that from a bucket at runtime [12]. Which payload arrived depended on the device's mobile country code [14]. A test phone in another country can receive a different program. The dev.to account of CERT Polska's findings says the campaign "treated the app store as a delivery mechanism rather than a filter." [15]

The ad side is easier to watch. Each ad sat in the Meta Ad Library under an identifier and a profile name. The two in this chain were 1101937705505412 under Britney Harris and 4635863290017072 under Kenneth Williams [6]. The second had fewer than 100 impressions [6]. One ad that size is easy to miss. Grouped by code and infrastructure evidence, the linked operation accounts for about 69% of the retained ad records and 59% of the promoted apps [2]. The gap between a PDF warning and a messaging listing is also visible in public data, before anyone installs anything [1][7].

I think the Play listing was the least informative artifact in this chain and the ad records were the most informative. This design fetches its payload after install [12], so store presence tells a defender that the loader got in and little about what it later ran.

What to watch

  • Whether the other 16 linked apps are still installable, and whether Google acts on copies already on phones.
  • Whether CERT Polska publishes the object-storage bucket and C2 indicators that carriers could block.
  • Reports of charges from the MCC 208 and 460 payload would show the operation billing outside Poland.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories