Shadow apps stealing from your phone bill – 200+ malware attacks exposed

A sophisticated cyberattack, targeting over 200 fake Android apps mimicking popular software like TikTok and GTA, is silently draining users’ bank accounts through their mobile carriers. Cybersecurity firm Zimperium has uncovered a multi-pronged operation with roots tracing back to Romania, Malaysia, and Croatia.

The ‘three-fold’ scam: how it works

This isn’t your typical dodgy app download. The scheme utilizes a layered approach – starting with automated subscription engines to trick users into paying for premium services without their knowledge. Then, the attackers burrow deeper, exploiting vulnerabilities to access SIM card data and identify preferred mobile carriers. Finally, a deceptive interface is presented to mask the malicious activity, mimicking legitimate confirmations.

200+ Apps, few on google play

200+ Apps, few on google play

While Google Play Protect offers automatic protection, a staggering 200+ apps are implicated, and remarkably, none appear to have been hosted on the official Google Play Store. This highlights the scale and sophistication of the operation, suggesting a deliberate attempt to circumvent established security protocols. Investigators pinpointed Malaysia as the epicenter, with 85% of victims located there, followed by Thailand and Croatia.

Long-term threat still active

Long-term threat still active

Despite being detected over a year ago in March 2025, the infrastructure supporting this scam remains operational. Activity peaked in September 2025, but ongoing monitoring reveals continued malicious activity as recently as January 2026. Experts warn that the potential for reactivation underscores the urgency of patching vulnerabilities, even if the malicious apps themselves are difficult to track down.

Carrier targeting – a broad assault

The attackers targeted a wide range of carriers, including DiGi, Marxis, Celcom, U Mobile, Telekom, AIS, Orange, Vodafone, TrueMove H, and dtac TriNet. This extensive reach demonstrates a well-funded and coordinated effort, posing a significant risk to millions of mobile users. Zimperium stresses that this attack isn’t simply a collection of isolated incidents; it’s a systemic breach that demands immediate attention.

Protect yourself – stick to official sources

Don’t be swayed by tempting offers from unofficial app stores. Rigorously scrutinize any app before downloading, and always opt for sources you trust. Be particularly cautious of automated subscription prompts and ensure you understand exactly what you are agreeing to. The fact that these apps aren't on the Play Store shouldn't lull you into a false sense of security – vigilance remains paramount.