Android ‘Toll Fraud’ Malware Detected, Subscribes Users to Premium Services Without Consent

The malware is largely distributed outside of Google Play because Google restricts the use of dynamic code loading by apps.

Advertisement
By Gadgets 360 Staff With Inputs From ANI | Updated: 4 July 2022 14:11 IST
Highlights
  • The apps harbouring the malware use "dynamic code loading"
  • The malware subscribes users to a premium service
  • The malware is largely distributed outside of Google Play

The apps harbouring the malware are usually classified as "toll fraud"

Photo Credit: Reuters

American tech giant Microsoft's 365 Defender Team recently revealed the growing popularity of malware that can subscribe users to a premium service without their knowledge.

In a blog post, the team explains that the attack from this form of malware is quite elaborate, while detailing the steps that the malware executes after infecting a device.

The apps harbouring the malware are usually classified as "toll fraud" and use "dynamic code loading" to carry out the attack, according to Microsoft.

Advertisement

The malware subscribes users to a premium service using their telecom provider's monthly bill which they are then forced to pay. It works by exploiting the WAP (wireless application protocol) used by cellular networks. That's why some forms of malware disable your Wi-Fi or just wait for you to go outside of Wi-Fi coverage.

This is where the aforementioned dynamic code loading comes into play. The malicious software then subscribes you to a service in the background, reads an OTP (one-time-password) you may receive before subscribing, fills out the OTP field on your behalf and hides the notification to cover its tracks.

The saving grace is that the malware is largely distributed outside of Google Play because Google restricts the use of dynamic code loading by apps, according to Microsoft.

Advertisement

Last month, cybersecurity platform Proofpoint discovered that the Emotet botnet — used by criminals to distribute malware around the world — has begun attempting to steal credit card information from unsuspecting users. The malware targets the popular Google Chrome browser, then sends the exfiltrated information to command-and-control servers.

The resurgence of the Emotet botnet comes over a year after Europol and international law enforcement agencies shut down the botnet's infrastructure in January 2021, and used the botnet to deliver software to remove the malware from infected computers.


What are the best tablets? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Note 15 Pro, Note 15 Pro+ 5G Could Launch in India on This Date
  2. Top Deals on OnePlus Smartphones During the Amazon Great Republic Day Sale
  3. OTT Releases of the Week (Jan 12 - Jan 18): Taskaree, 120 Bahadur, and More
  4. OnePlus 15T Launch Timeline, Chipset Details Leaked
  5. Amazon Great Republic Day Sale: Top Deals on Premium Smartphones
  6. NASA Says the Year 2025 Almost Became Earth's Hottest Recorded Year Ever
  7. Resident Evil Requiem Gets New Leon Gameplay at Resident Evil Showcase
  8. Wicked: For Good OTT Release: Know When, Where to Watch the Musical Fantasy
  9. Here's How Much the Vivo X200T Could Cost in India: See Expected Specs
  10. Redmi Buds 8 Lite Launched With ANC, Up to 36 Hours Total Battery Life
  1. Resident Evil Requiem Gets New Leon Gameplay at Resident Evil Showcase
  2. After ChatGPT Translate, Google Releases Multiple Open-Source Translation Models
  3. Realme Buds Clip India Launch Timeline Confirmed: Expected Specifications, Features
  4. NASA's James Webb Space Telescope Might Have Spotted Hidden Supermassive Black Holes
  5. Amazon Great Republic Day Sale: Top Laptop Deals Under Rs. 40,000
  6. OnePlus 15T Launch Timeline, Chipset Details Leaked: Expected Specifications, Features
  7. Vivo X200T Price in India, Design, Key Specifications Tipped Ahead of Launch
  8. India Becomes World’s Second Largest 5G Base with 400M+ Users, Says Union Minister Jyotiraditya Scindia
  9. Instagram Will Now Let You Dub and Lip Sync Reels Into Five Indian Languages
  10. Bitcoin Trades Above $95,000 as ETF Inflows Drive Market Sentiment
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.