Of 1,235 Meta advertisements that Poland’s national CERT preserved, 852 led Android users to one of 17 Google Play apps built to run up charges through premium-rate text messages and weekly carrier billing. Each premium text cost 30.75 Polish zloty, about $7.97 at the exchange rate The Register used, and the apps could send it without the owner knowingly agreeing to a purchase.
The campaign was aimed at Poland. Its code checked the phone’s SIM before doing anything harmful, so the same apps behave like ordinary utilities elsewhere.
The ads, the apps and the 852 count
CERT Polska, the incident response team that publishes its findings at cert.pl, laid out the evidence in a technical analysis: 1,235 preserved ads shown under 74 profile names, with 852 of them tied to 17 Google Play apps through shared code and infrastructure. Six of the apps held recovered toll-fraud components and eleven carried related loaders. The ads told Polish users that a PDF app they had installed had expired and steered them to a messenger or utility app instead.
The reference sample was an app called Messenger Pro. ITReseller, a Polish trade site, listed other titles from the cluster, among them Phone Cleaner Master, PDF Scanner Art, Max Messenger, Cool Wallpaper and Text Chat. Messenger Pro asked to become the phone’s default messaging app and then ran encrypted code that fetched the billing modules.
The 30.75 zloty text and the weekly subscription
CERT Polska’s analysts found three premium short codes, 92505, 92512 and 92513, all registered with the national regulator UKE at 30.75 PLN per message. The Register converted that charge to $7.97 per text and reported a second route on top: direct carrier billing through a provider called Teleaudio at 17 PLN, about $4.41, charged weekly. Shopifreaks adds that the billing options were live across Poland’s four major mobile operators, Orange, T-Mobile, Play and Polkomtel.
Because premium texts and carrier billing show up on a phone bill rather than a card statement, an affected owner might notice only when the monthly charge arrives. The weekly route compounds the same problem: at 17 PLN a week, a subscription left running for four weeks would bill 68 PLN, roughly $17.64 at the same conversion, and four premium texts at the registered rate would reach 123 PLN, about $31.88.
The loader went through four layers before any fraud happened: a base package with an encrypted first stage, a check of the package name and the SIM’s mobile country code, a country gate that applied a per-country policy, and a payload router that picked the final module. Only devices with Poland’s code, MCC 260, received the toll-fraud payload, and CERT Polska observed the command server assigning live premium-SMS and carrier-billing jobs, evidence that the operation was running and was not merely a distribution effort.
The pattern in the ads matters for anyone reconstructing how victims arrived. Instead of promoting a messaging app outright, the creatives told people that a PDF tool they believed they had installed had expired, which sent them to a Play listing that looked like the obvious replacement. The user who followed the link landed on a store page that Google was still hosting, with an install button and a rating, and nothing on the way marked the app as part of a paid-acquisition fraud chain. CERT Polska’s attribution rests on shared code, shared server infrastructure and 20 parent domains registered through Amazon’s registrar between July and September 2026, evidence that ties the 17 apps to one operator without naming who that operator is.
Platform responses and what remained live
CERT Polska reported its findings to Google on 15 September 2026, and Google pulled Messenger Pro from Google Play the same day, though removal from the store does not uninstall copies already on phones. Meta deleted the advertisements that had been reported. The team’s own warning, quoted by Shopifreaks, was that the command infrastructure stayed active, new packages appeared after the removals, and previously installed copies could still reach operator-controlled servers.
The Register quoted Kacper Ratajczak, a senior security engineer at CERT Polska, on where responsibility sits: “Meta supplied paid acquisition aimed at Polish users. Google Play supplied the installation path that users treat as reviewed and trustworthy.” ITReseller’s account of the report adds that CERT Polska considers an official store listing something that “should not be treated as unambiguous security guarantee.”
A threat-intelligence summary of the report stresses the point that the tasking was active, citing CERT Polska’s observation of live jobs for both fraud mechanisms. Shopifreaks notes that Google and Meta each acted only on the items CERT Polska reported to them.
No source has published a count of the people who installed the apps or the total amount billed, and neither Meta nor Google has stated how many of the 852 ads were served before takedown. The 852 figure counts ads preserved by CERT Polska, which leaves open how many more ran unseen.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Supplements now rank as the fifth-leading cause of death from liver disease.
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- General Motors is switching on cameras that record inside your vehicle by update
- A geomagnetic storm is forecast to hit Earth today, pushing the northern lights unusually far south