Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Malicious ads led Polish users to Google Play apps that charged their phone bills

CERT Polska linked 852 Meta ads to 17 Google Play apps in a toll-fraud operation. We explain the risk and actions for users and employers.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
29 September 2026
READING TIME
10 min read
TOPIC
Human Security
Malicious ads led Polish users to Google Play apps that charged their phone bills

A Facebook ad warned that a PDF application had expired. Its link opened Google Play, but instead of an update the user installed a messaging app called Messenger Pro. The app worked well enough to ask to become the default text-message handler, while hidden code could initiate premium messages and subscriptions charged to a Polish mobile account.

CERT Polska’s investigation linked 852 ads displayed under 60 profile names to 17 applications on Google Play. The case breaks two convenient assumptions: an ad displayed by a major platform is not an endorsement, and an app’s presence in an official store does not remove the need to assess its purpose and permissions.

How users reached the trap

The investigation began with two ads found on 14 September. They claimed that PDF software had expired even though they directed users to an app with a different purpose. CERT Polska eventually collected 1,235 Meta ads displayed under 74 identified profile names. Of those, 852 ads promoted 17 applications linked by code or infrastructure to the toll-fraud operation.

Researchers recovered toll-fraud components or direct payload links from six apps. Eleven more contained malicious loaders connected to the same operation, although their final fraud payloads could not be recovered. That distinction matters: their relationship to the operation is supported by evidence, but the evidential level is not identical for every package.

Messenger Pro displayed a functioning inbox and could plausibly ask to become the default SMS app. That role granted access to read, receive and send text messages. A hidden, multi-stage loader fetched further code and selected a branch by country and mobile network. Poland’s mobile country code directed devices into a fraud-capable path.

What toll fraud means

Toll fraud enrols a subscriber in a paid service without their informed consent. During the investigation, an active command-and-control server assigned tasks involving both premium-rate SMS messages and Direct Carrier Billing, which adds a payment to a mobile bill or deducts it from prepaid credit.

Malicious code can bind traffic to the mobile network, open a payment page, supply the phone number, intercept a verification message and confirm the purchase. The user may never see the full page or confirmation. CERT Polska observed, among other examples, a one-off charge of PLN 30.75 and an offer costing PLN 17 every seven days.

The payment aggregators and premium-number operators were not identified as the malware campaign’s operators. Their billing mechanisms were abused. CERT Polska also did not attribute the campaign to a named person, organisation or state.

What to do on a personal phone

Review recently installed apps, particularly messaging tools, phone cleaners, PDF scanners and utilities found through advertising. Pay attention to Messenger Pro and Phone Cleaner Master, which appear in the analysis, but do not limit the review to those two names. CERT Polska’s report contains the fuller list and explains the evidence for each package.

Check which app is the default SMS handler, which programs can draw over other apps and which have access to messages, phone state, contacts and notifications. Remove unnecessary roles and permissions. A PDF tool does not need text-message access, and a storage cleaner should not control carrier billing.

Review the mobile bill and the operator’s list of additional services. Look for short codes, carrier payments, subscriptions and recurring amounts you do not recognise. Contact the carrier through an official channel, ask it to explain the charges, cancel unwanted services and block premium SMS or Direct Carrier Billing where those features are not needed.

If a suspicious app was the default text-message program, it may have seen codes and message content. From a trusted device, review critical accounts, change passwords where compromise is plausible and inspect active sessions. If unusual phone behaviour continues, consider a manufacturer-supported factory reset after preserving essential data and evidence.

Our smartphone security guide covers the basics. The key rule for the future is simple: do not install an app merely because an ad says existing software has “expired”. Start updates from the app itself, system settings or a store listing that you found independently.

What employers should do with managed phones

A work phone can combine carrier payments, email, messaging, customer contacts and authentication codes. A policy that says “use only the official store” is therefore insufficient. Organisations need an application inventory, installation restrictions, controls over high-risk roles and a process for reporting an unusual phone bill.

On managed devices, use an approved-app catalogue or managed store, block unnecessary installation sources and restrict changes to the default SMS handler. The carrier can disable premium services and bill-based payments for lines that do not require them.

Finance and IT should jointly monitor small recurring charges. A single PLN 17 or PLN 30 item may remain below an alert threshold, but similar entries across several lines indicate a campaign. The help desk should know how to preserve the package name, installation time, permission screenshots and billing evidence without immediately destroying useful artefacts.

Training should show the complete trust chain: a paid ad, an official store, a working visible feature and a permission request that appears reasonable. These realistic scenarios belong in employee cybersecurity training, rather than a programme limited to spotting spelling mistakes in email.

Source facts and Breachroad conclusions

The CERT Polska investigation is the source for the advertising and application counts, technical flow, Poland-specific targeting, command-and-control tasks and observed charges. The team did not attribute the operation to a particular identity and did not claim equal evidence for every app.

The phone, account and billing checklist, as well as the employer controls, are Breachroad recommendations. App stores and advertising platforms reduce some risks, but they do not replace the user’s or organisation’s assessment of whether an app is necessary and whether a permission matches its function.

SHARE / COPY